CVE-2026-98362: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate dvfs_get_idx() may return an out-of-range index if the SCP firmware is buggy or returns a stale value. Only negative indexes were rejected, so a large index walked past info->opps and could treat garbage as a clock rate (KASAN OOB / wrong frequency to consumers). The missing upper bound dates back to the original SCPI clock driver. Treat indexes >= opp count as invalid and return 0, same as idx < 0.
Affected products
- Linux Linux: from 4.4, before 5.10.271 (fixed in 5.10.271); from 5.11, before 5.15.222 (fixed in 5.15.222); from 5.16, before 6.1.189 (fixed in 6.1.189); from 6.2, before 6.6.158 (fixed in 6.6.158); from 6.7, before 6.12.112 (fixed in 6.12.112); from 6.13, before 6.18.54 (fixed in 6.18.54); …
Published 2026-10-06. Last modified 2026-10-06.