{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.111-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  cpufreq: zero-initialize policy cpumask before sysfs publication  cpufreq_policy_alloc() allocates policy-\u003ecpus with alloc_cpumask_var(), i.e. without __GFP_ZERO, unlike the sibling related_cpus and real_cpus masks. With CONFIG_CPUMASK_OFFSTACK=y the mask is a separate kmalloc_node() allocation, so its bitmap holds whatever the slab allocator left behind:    cpufreq_online()     cpufreq_policy_alloc()       alloc_cpumask_var(\u0026policy-\u003ecpus)    /* bitmap is uninitialized */       kobject_init_and_add()              /* policy%u/ appears in sysfs */     cpufreq_policy_online()       cpumask_copy(policy-\u003ecpus, cpumask_of(cpu))  /* first valid value */  This leaves a window in which the sysfs attributes are already reachable while policy-\u003ecpus is still garbage. show()/store() gate on policy_is_inactive(), i.e. cpumask_empty(policy-\u003ecpus), so a non-zero bitmap makes them run the attribute callbacks on a policy that is not initialized yet.  Fix this by using zalloc_cpumask_var() for policy-\u003ecpus.",
  "id": "DEBIAN-CVE-2026-97905",
  "modified": "2026-09-29T10:47:28.773867336Z",
  "published": "2026-09-25T11:17:17.403Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-97905"
    }
  ],
  "upstream": [
    "CVE-2026-97905"
  ]
}