Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98362— clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: clk: scpi: 在 scpi_dvfs_recalc_rate 中对 DVFS 索引进行边界检查 如果 SCP 固件存在缺陷或返回了过时(stale)值, 可能返回超出范围的索引。此前仅拒绝了负数索引,因此较大的索引会越界访问 ,导致将垃圾数据误认为时钟频率(引发 KASAN 越界访问/向消费者报告错误的频率)。这一缺失的上界检查问题可追溯至原始的 SCPI 时钟驱动。 现在将大于等于 OPP 计数的索引视为无效,并返回 0,处理方式与索引小于 0 时相同。

AI Predicted 5.5 Difficulty: Hard EPSS 0.17% · P6

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux cd52c2a4b5c43631e429d06dce12e08b0cab477f< 6e3b55823da8ef0d99621efb422cc29f50d7f280 affected
cd52c2a4b5c43631e429d06dce12e08b0cab477f< 7204095917aeaac89db7377c29a457351a19b076 affected
cd52c2a4b5c43631e429d06dce12e08b0cab477f< 0f89e2ac0e945da2ce798f6a61aebf9d291c2e0a affected
cd52c2a4b5c43631e429d06dce12e08b0cab477f< 56b7a9d89c67932bf11b71e3b6d17941fc24a393 affected
cd52c2a4b5c43631e429d06dce12e08b0cab477f< a82b274697d0876b478594ca78ad1e6cb062467b affected
cd52c2a4b5c43631e429d06dce12e08b0cab477f< e1188332a9110cf3635fe286481ee38305b3c2b6 affected
cd52c2a4b5c43631e429d06dce12e08b0cab477f< 108c46e8dacc4a0e472a74f98171115d49cbc079 affected
cd52c2a4b5c43631e429d06dce12e08b0cab477f< 70f4b78d560e592cbf3325b162424737d032fc1d affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98362

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate dvfs_get_idx() may return an out-of-range index if the SCP firmware is buggy or returns a stale value. Only negative indexes were rejected, so a large index walked past info->opps and could treat garbage as a clock rate (KASAN OOB / wrong frequency to consumers). The missing upper bound dates back to the original SCPI clock driver. Treat indexes >= opp count as invalid and return 0, same as idx < 0.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux cd52c2a4b5c43631e429d06dce12e08b0cab477f ~ 6e3b55823da8ef0d99621efb422cc29f50d7f280 -
Linux Linux 4.4 -

II. Public POCs for CVE-2026-98362

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98362

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98362 (8)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98281 7.8 HIGH futex: Also allocate private hash on vfork()
CVE-2026-98324 7.8 HIGH dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98362

No comments yet


Leave a comment