cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path
Published May 8, 2026
7.8
HIGHCVSS 3.1
EPSS 0.18%
Description
When kobject_init_and_add() fails, cpufreq_dbs_governor_init() calls kobject_put(&dbs_data->attr_set.kobj).
The kobject release callback cpufreq_dbs_data_release() calls gov->exit(dbs_data) and kfree(dbs_data), but the current error path then calls gov->exit(dbs_data) and kfree(dbs_data) again, causing a double free.
Keep the direct kfree(dbs_data) for the gov->init() failure path, but after kobject_init_and_add() has been called, let kobject_put() handle the cleanup through cpufreq_dbs_data_release().
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints-
- Version
-
- Version 5.1.6StatusaffectedConstraints<5.2
- Version
-
- Version 5.2StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.2
- Version 5.10.253StatusunaffectedConstraints<=5.10.*
- Version 5.15.209StatusunaffectedConstraints<=5.15.*
- Version 6.1.168StatusunaffectedConstraints<=6.1.*
- Version 6.12.81StatusunaffectedConstraints<=6.12.*
- Version 6.18.22StatusunaffectedConstraints<=6.18.*
- Version 6.19.12StatusunaffectedConstraints<=6.19.*
- Version 6.6.134StatusunaffectedConstraints<=6.6.*
- Version 7.0StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.2 · < 5.10.253
- ≥ 5.11 · < 6.1.168
- ≥ 6.2 · < 6.6.134
- ≥ 6.7 · < 6.12.81
- ≥ 6.13 · < 6.18.22
- ≥ 6.19 · < 6.19.12
- 5.1.6
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
No data.
Red Hat Enterprise Linux 10
kernel
Affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Affected
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- https://access.redhat.com/security/cve/CVE-2026-43328 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2468079 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-28612 Advisory
- https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-43328.mbox
- https://git.kernel.org/stable/c/019ea28629720c220daedf38107c8787f330dc05 Patch
- https://git.kernel.org/stable/c/3bf9d023d2329a0e5379f2fd09d06ef09729cd9d Patch
- https://git.kernel.org/stable/c/427d048e4f6acbfa01b5a8062449fe0ee8987c0d Patch
- https://git.kernel.org/stable/c/4b9118e93d2499bb2808ef3742fa0ce06f4f8117
- https://git.kernel.org/stable/c/56bc91ee78babe9578585a2bc137abc4b3115ff3 Patch
- https://git.kernel.org/stable/c/6dcf9d0064ce2f3e3dfe5755f98b93abe6a98e1e Patch
- https://git.kernel.org/stable/c/d2703b4f8fb7cc6f0dfdb2dc2359cc46189e7357 Patch
- https://git.kernel.org/stable/c/da39ee627fd82b52068d4d5f115749a8b7d271f9 Patch
- https://nvd.nist.gov/vuln/detail/CVE-2026-43328
- https://www.cve.org/CVERecord?id=CVE-2026-43328
Change history (0)
No recorded changes yet.