SB2026072073 - Improper access control in Linux kernel x86 uniwill driver



SB2026072073 - Improper access control in Linux kernel x86 uniwill driver

Published: July 20, 2026

Security Bulletin ID SB2026072073
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper access control (CVE-ID: CVE-2026-64143)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause permanent hardware damage to the battery.

The vulnerability exists due to improper access control in the uniwill-laptop battery charging limit feature when forcing the driver to enable the charging threshold interface on unsupported devices. A local user can enable the charging limit through the force module parameter to cause permanent hardware damage to the battery.

The issue affects some older device models that do not properly implement the charging threshold interface.


Remediation

Install update from vendor's website.