CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's cpufreq subsystem, specifically in the handling of the _OSC negotiation process, where a use-after-free and double free condition can occur due to improper management of memory pointers. This flaw could lead to potential system crashes or arbitrary code execution, posing a significant risk to system stability and security. Organizations using affected Linux distributions should prioritize patching this vulnerability to mitigate the associated risks.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: cpufreq: pcc: fix use-after-free and double free in _OSC evaluation pcc_cpufreq_do_osc() calls acpi_evaluate_object() twice for the two-phase _OSC negotiation. Between the two calls it freed output.pointer but left output.length unchanged. Since acpi_evaluate_object() treats a non-zero length with a non-NULL pointer as an existing buffer to write into, the second call wrote into freed memory (use-after-free). The subsequent kfree(output.pointer) at out_free then freed the same pointer a second time (double free). Reset output.pointer to NULL and output.length to ACPI_ALLOCATE_BUFFER after freeing the first result, so ACPICA allocates a fresh buffer for each phase independently.