---
id: CVE-2026-98362
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate

  dvfs_get_idx() may return an out-of-range index if the SCP firmware is
  buggy or returns a stale value
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate

  dvfs_get_idx() may return an out-of-range index if the SCP firmware is
  buggy or returns a stale value. Only …
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= cd52c2a4b5c43631e429d06dce12e08b0cab477f <
    6e3b55823da8ef0d99621efb422cc29f50d7f280
  - >-
    Linux >= cd52c2a4b5c43631e429d06dce12e08b0cab477f <
    7204095917aeaac89db7377c29a457351a19b076
  - >-
    Linux >= cd52c2a4b5c43631e429d06dce12e08b0cab477f <
    0f89e2ac0e945da2ce798f6a61aebf9d291c2e0a
  - >-
    Linux >= cd52c2a4b5c43631e429d06dce12e08b0cab477f <
    56b7a9d89c67932bf11b71e3b6d17941fc24a393
  - >-
    Linux >= cd52c2a4b5c43631e429d06dce12e08b0cab477f <
    a82b274697d0876b478594ca78ad1e6cb062467b
  - >-
    Linux >= cd52c2a4b5c43631e429d06dce12e08b0cab477f <
    e1188332a9110cf3635fe286481ee38305b3c2b6
  - >-
    Linux >= cd52c2a4b5c43631e429d06dce12e08b0cab477f <
    108c46e8dacc4a0e472a74f98171115d49cbc079
  - >-
    Linux >= cd52c2a4b5c43631e429d06dce12e08b0cab477f <
    70f4b78d560e592cbf3325b162424737d032fc1d
  - Linux 4.4
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:30.090'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98362'
references:
  - url: 'https://git.kernel.org/stable/c/0f89e2ac0e945da2ce798f6a61aebf9d291c2e0a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/108c46e8dacc4a0e472a74f98171115d49cbc079'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/56b7a9d89c67932bf11b71e3b6d17941fc24a393'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6e3b55823da8ef0d99621efb422cc29f50d7f280'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/70f4b78d560e592cbf3325b162424737d032fc1d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7204095917aeaac89db7377c29a457351a19b076'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a82b274697d0876b478594ca78ad1e6cb062467b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e1188332a9110cf3635fe286481ee38305b3c2b6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.391Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate

dvfs_get_idx() may return an out-of-range index if the SCP firmware is
buggy or returns a stale value. Only negative indexes were rejected, so a
large index walked past info->opps and could treat garbage as a clock rate
(KASAN OOB / wrong frequency to consumers). The missing upper bound dates
back to the original SCPI clock driver.

Treat indexes >= opp count as invalid and return 0, same as idx < 0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
