Back to overview

CVE-2026-64511

Description
In the Linux kernel, the following vulnerability has been resolved: ACPI: NFIT: core: Fix possible NULL pointer dereference After commit 9b311b7313d6 ("ACPI: NFIT: Install Notify() handler before getting NFIT table"), acpi_nfit_probe() installs an ACPI notify handler for the NFIT device before checking the presence of the NFIT table. If that table is not there, 0 is returned without allocating the acpi_desc object and setting the driver data pointer of the NFIT device. If the platform firmware triggers an NFIT_NOTIFY_UC_MEMORY_ERROR notification on the NFIT device at that point, acpi_nfit_uc_error_notify() will dereference a NULL pointer. Prevent that from occurring by adding an acpi_desc check against NULL to acpi_nfit_uc_error_notify().

Metadata

CVE ID
CVE-2026-64511
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 15:36 UTC
Published
2026-07-25 08:52 UTC
Last updated
2026-07-25 08:52 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 9b311b7313d6c104dd4a2d43ab54536dce07f960 < a44343fe230aa48c74ef09830f3c5c90848b257e, 9b311b7313d6c104dd4a2d43ab54536dce07f960 < 3c8f73b0fbdf956c98e2329d5aaea3ad09a9cfb6, 9b311b7313d6c104dd4a2d43ab54536dce07f960 < 452945662fd8e9862a2d2043239c7ee1815d1ac4, 9b311b7313d6c104dd4a2d43ab54536dce07f960 < 873576e585da5d0fc5debbab74eed565c0acea99 …
Linux Linux 6.6, 0 < 6.6, 6.6.145 ≤ 6.6.*, 6.12.96 ≤ 6.12.* …
Back to overview