CVE-2026-98362
Received Received - Intake

SCPI Clock Driver DVFS Index Out-of-Bounds in Linux Kernel

Vulnerability report for CVE-2026-98362, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate dvfs_get_idx() may return an out-of-range index if the SCP firmware is buggy or returns a stale value. Only negative indexes were rejected, so a large index walked past info->opps and could treat garbage as a clock rate (KASAN OOB / wrong frequency to consumers). The missing upper bound dates back to the original SCPI clock driver. Treat indexes >= opp count as invalid and return 0, same as idx < 0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
Linux Linux cd52c2a4b5c43631e429d06dce12e08b0cab477f
Linux Linux cd52c2a4b5c43631e429d06dce12e08b0cab477f
Linux Linux cd52c2a4b5c43631e429d06dce12e08b0cab477f
Linux Linux cd52c2a4b5c43631e429d06dce12e08b0cab477f
Linux Linux cd52c2a4b5c43631e429d06dce12e08b0cab477f
Linux Linux cd52c2a4b5c43631e429d06dce12e08b0cab477f
Linux Linux cd52c2a4b5c43631e429d06dce12e08b0cab477f
Linux Linux cd52c2a4b5c43631e429d06dce12e08b0cab477f
Linux Linux 4.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a missing upper bound check in the SCPI clock driver's DVFS index handling. The function dvfs_get_idx() could return an out-of-range index if the SCP firmware is faulty or provides stale data. Previously, only negative indexes were rejected, allowing large positive indexes to access invalid memory (KASAN OOB) and potentially treat garbage data as a clock rate, leading to incorrect frequencies for consumers.

Impact Analysis

This vulnerability could cause system instability or crashes if the SCP firmware returns invalid data. It may lead to incorrect clock rates being applied, potentially causing hardware malfunctions or performance issues. Systems relying on SCPI for dynamic voltage and frequency scaling could experience unexpected behavior.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98362. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart