In the Linux kernel, the following vulnerability has been resolved:
cpufreq: pcc: fix use-after-free and double free in _OSC evaluation
pcccpufreqdoosc() calls acpievaluateobject() twice for the two-phase OSC negotiation. Between the two calls it freed output.pointer but left output.length unchanged. Since acpievaluateobject() treats a non-zero length with a non-NULL pointer as an existing buffer to write into, the second call wrote into freed memory (use-after-free). The subsequent kfree(output.pointer) at out_free then freed the same pointer a second time (double free).
Reset output.pointer to NULL and output.length to ACPIALLOCATEBUFFER after freeing the first result, so ACPICA allocates a fresh buffer for each phase independently.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64372.json"
}