MEDIUM

CVE-2026-53121

Linux Linux Kernel 2026-06-24 CVSS v3.1
CVSS
5.5

Description

In the Linux kernel, the following vulnerability has been resolved:

amd-pstate: Fix memory leak in amd_pstate_epp_cpu_init()

On failure to set the epp, the function amd_pstate_epp_cpu_init()
returns with an error code without freeing the cpudata object that was
allocated at the beginning of the function.

Ensure that the cpudata object is freed before returning from the
function.

This memory leak was discovered by Claude Opus 4.6 with the aid of
Chris Mason's AI review-prompts
(https://github.com/masoncl/review-prompts/tree/main/kernel).

Summary dbcve.org

Memory leak in Linux kernel's amd-pstate driver. The amd_pstate_epp_cpu_init() function allocates a cpudata object at the start but fails to free it when the function returns an error due to failure in setting the Energy Performance Preference (EPP), leading to resource exhaustion over repeated failures.

Mitigation

Apply the kernel patch that adds proper cleanup to free the cpudata object on the error path before returning from amd_pstate_epp_cpu_init(). This is a code-level fix requiring kernel development expertise.

Patch Commit

Weakness (CWE)

CWE-401 Memory Leak

EPSS Score

0.11%
Probability of exploitation in next 30 days
1.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE