Back

HIGH

cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path

Published May 8, 2026

Description

When kobject_init_and_add() fails, cpufreq_dbs_governor_init() calls kobject_put(&dbs_data->attr_set.kobj).

The kobject release callback cpufreq_dbs_data_release() calls gov->exit(dbs_data) and kfree(dbs_data), but the current error path then calls gov->exit(dbs_data) and kfree(dbs_data) again, causing a double free.

Keep the direct kfree(dbs_data) for the gov->init() failure path, but after kobject_init_and_add() has been called, let kobject_put() handle the cleanup through cpufreq_dbs_data_release().

Affected products

Remediation

No remediation recorded yet.

Weaknesses (2)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published May 8, 2026
Updated Jun 1, 2026
Reserved May 1, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 8, 2026
ENISA EUVD
Assigner Linux
Published May 8, 2026
Updated Jun 1, 2026
Exploited since n/a
EUVD-2026-28612