clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate

Summary

CVECVE-2026-98362
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-10-06 09:18:30 UTC
Updated2026-10-06 09:18:30 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate dvfs_get_idx() may return an out-of-range index if the SCP firmware is buggy or returns a stale value. Only negative indexes were rejected, so a large index walked past info->opps and could treat garbage as a clock rate (KASAN OOB / wrong frequency to consumers). The missing upper bound dates back to the original SCPI clock driver. Treat indexes >= opp count as invalid and return 0, same as idx < 0.

Risk And Classification

EPSS: 0.001720000 probability, percentile 0.059920000 (date 2026-10-06)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected cd52c2a4b5c43631e429d06dce12e08b0cab477f 6e3b55823da8ef0d99621efb422cc29f50d7f280 git Not specified
CNA Linux Linux affected cd52c2a4b5c43631e429d06dce12e08b0cab477f 7204095917aeaac89db7377c29a457351a19b076 git Not specified
CNA Linux Linux affected cd52c2a4b5c43631e429d06dce12e08b0cab477f 0f89e2ac0e945da2ce798f6a61aebf9d291c2e0a git Not specified
CNA Linux Linux affected cd52c2a4b5c43631e429d06dce12e08b0cab477f 56b7a9d89c67932bf11b71e3b6d17941fc24a393 git Not specified
CNA Linux Linux affected cd52c2a4b5c43631e429d06dce12e08b0cab477f a82b274697d0876b478594ca78ad1e6cb062467b git Not specified
CNA Linux Linux affected cd52c2a4b5c43631e429d06dce12e08b0cab477f e1188332a9110cf3635fe286481ee38305b3c2b6 git Not specified
CNA Linux Linux affected cd52c2a4b5c43631e429d06dce12e08b0cab477f 108c46e8dacc4a0e472a74f98171115d49cbc079 git Not specified
CNA Linux Linux affected cd52c2a4b5c43631e429d06dce12e08b0cab477f 70f4b78d560e592cbf3325b162424737d032fc1d git Not specified
CNA Linux Linux affected 4.4 Not specified
CNA Linux Linux unaffected 4.4 semver Not specified
CNA Linux Linux unaffected 5.10.271 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.222 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.189 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.158 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.112 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.54 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.8 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc4 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/e1188332a9110cf3635fe286481ee38305b3c2b6 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a82b274697d0876b478594ca78ad1e6cb062467b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/108c46e8dacc4a0e472a74f98171115d49cbc079 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/7204095917aeaac89db7377c29a457351a19b076 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/56b7a9d89c67932bf11b71e3b6d17941fc24a393 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/6e3b55823da8ef0d99621efb422cc29f50d7f280 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/70f4b78d560e592cbf3325b162424737d032fc1d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/0f89e2ac0e945da2ce798f6a61aebf9d291c2e0a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report