Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97904— cpufreq: initialize policy rwsem before sysfs publication

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已得到修复: cpufreq:在发布 sysfs 之前初始化策略(policy)的读写信号量(rwsem) 函数在调用 创建策略(policy)的 sysfs 目录及其默认属性之后,才初始化 。因此,在信号量尚未初始化的情况下,sysfs 访问可能会触发策略回调函数。 应在发布策略 kobject 之前初始化 ,以确保 sysfs 回调函数始终能看到一个已正确初始化的信号量。

AI Predicted 5.5 Difficulty: Hard EPSS 0.21% · P10

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 2fc3384dc75bf7333384c7a16d12c796f61c3f56< c9d8435814f2ac533c40fe3f35d94235bc3a9443 affected
2fc3384dc75bf7333384c7a16d12c796f61c3f56< 82a54923700da5de83ce2b26c0b43f6b5005c8f1 affected
2fc3384dc75bf7333384c7a16d12c796f61c3f56< b14987a0f73777644099f47f01aba3b0f9dc6c27 affected
2fc3384dc75bf7333384c7a16d12c796f61c3f56< b22193eea2ce32c39dda5e09f9c2be2f3fd7eb4a affected
2fc3384dc75bf7333384c7a16d12c796f61c3f56< dc11263cb05ed519758fd135fe08d611bad1f241 affected
2fc3384dc75bf7333384c7a16d12c796f61c3f56< 27c9b491bf7604e83b50c3bbfa18a30266ff345f affected
2fc3384dc75bf7333384c7a16d12c796f61c3f56< 2cee937f779f69b195b37bbec1e888da9bfe9d58 affected
2fc3384dc75bf7333384c7a16d12c796f61c3f56< 3e5d1bf4bd687beb2cb4e32a07af695455925588 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97904

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
cpufreq: initialize policy rwsem before sysfs publication
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: cpufreq: initialize policy rwsem before sysfs publication cpufreq_policy_alloc() initializes policy->rwsem after kobject_init_and_add() has created the policy sysfs directory and its default attributes. A sysfs access can therefore reach a policy callback before the semaphore has been initialized. Initialize policy->rwsem before publishing the policy kobject so sysfs callbacks always see an initialized semaphore.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 2fc3384dc75bf7333384c7a16d12c796f61c3f56 ~ c9d8435814f2ac533c40fe3f35d94235bc3a9443 -
Linux Linux 4.2 -

II. Public POCs for CVE-2026-97904

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97904

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-97904 (8)

Same Patch Batch · Linux · 2026-09-25 · 372 CVEs total

CVE-2026-100075 9.8 CRITICAL RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
CVE-2026-97555 8.8 HIGH smb: client: fix heap overflow in DACL owner/group rewrite
CVE-2026-97957 8.8 HIGH net: hinic: fix mailbox segment buffer overflow
CVE-2026-97527 8.8 HIGH scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock
CVE-2026-97528 8.8 HIGH scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error
CVE-2026-98115 8.8 HIGH ksmbd: safely drain sessions during logoff
CVE-2026-97525 8.2 HIGH x86/mm/pat: Allocate split page tables as kernel page tables
CVE-2026-98069 8.1 HIGH net/rds: acquire the fastpath locks in rds_conn_shutdown()
CVE-2026-97573 8.1 HIGH bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()
CVE-2026-97570 8.1 HIGH bnxt_en: Bound SW TPA IDs to prevent crashes
CVE-2026-98130 8.1 HIGH sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
CVE-2026-98070 8.1 HIGH net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()
CVE-2026-98122 7.8 HIGH vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del()
CVE-2026-97575 7.8 HIGH media: v4l2-ctrls: validate AV1 tile counts
CVE-2026-97576 7.8 HIGH media: v4l2-ctrls: validate HEVC tile counts
CVE-2026-98112 7.8 HIGH ksmbd: fix listener task lifetime on netdev events
CVE-2026-98002 7.8 HIGH iommu/amd: Fix ineffective error check in nested domain allocation
CVE-2026-98116 7.8 HIGH ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF
CVE-2026-97580 7.8 HIGH media: rkvdec: bound HEVC tile loops and PPS id to the array capacity
CVE-2026-97940 7.8 HIGH ipv6: fix fib6 walker UAF on seq stop

Showing top 20 of 372 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-97904

No comments yet


Leave a comment