Answer in brief
CVE-2026-98362 records a Unknown severity vulnerability in clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=cd52c2a4b5c43631e429d06dce12e08b0cab477f <6e3b55823da8ef0d99621efb422cc29f50d7f280 || >=cd52c2a4b5c43631e429d06dce12e08b0cab477f <7204095917aeaac89db7377c29a457351a19b076 || >=cd52c2a4b5c43631e429d06dce12e08b0cab477f <0f89e2ac0e945da2ce798f6a61aebf9d291c2e0a || >=cd52c2a4b5c43631e429d06dce12e08b0cab477f <56b7a9d89c67932bf11b71e3b6d17941fc24a393 || >=cd52c2a4b5c43631e429d06dce12e08b0cab477f <a82b274697d0876b478594ca78ad1e6cb062467b || >=cd52c2a4b5c43631e429d06dce12e08b0cab477f <e1188332a9110cf3635fe286481ee38305b3c2b6 || >=cd52c2a4b5c43631e429d06dce12e08b0cab477f <108c46e8dacc4a0e472a74f98171115d49cbc079 || >=cd52c2a4b5c43631e429d06dce12e08b0cab477f <70f4b78d560e592cbf3325b162424737d032fc1d | 6e3b55823da8ef0d99621efb422cc29f50d7f280, 7204095917aeaac89db7377c29a457351a19b076, 0f89e2ac0e945da2ce798f6a61aebf9d291c2e0a, 56b7a9d89c67932bf11b71e3b6d17941fc24a393, a82b274697d0876b478594ca78ad1e6cb062467b, e1188332a9110cf3635fe286481ee38305b3c2b6, 108c46e8dacc4a0e472a74f98171115d49cbc079, 70f4b78d560e592cbf3325b162424737d032fc1d |
| Linux/Linuxgeneric | 4.4 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate dvfs_get_idx() may return an out-of-range index if the SCP firmware is buggy or returns a stale value. Only negative indexes were rejected, so a large index walked past info->opps and could treat garbage as a clock rate (KASAN OOB / wrong frequency to consumers). The missing upper bound dates back to the original SCPI clock driver. Treat indexes >= opp count as invalid and return 0, same as idx < 0.
Quoted source text, attributed separately from HOL analysis.