SB2026072073 - Improper access control in Linux kernel x86 uniwill driver
Published: July 20, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2026-64143)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause permanent hardware damage to the battery.
The vulnerability exists due to improper access control in the uniwill-laptop battery charging limit feature when forcing the driver to enable the charging threshold interface on unsupported devices. A local user can enable the charging limit through the force module parameter to cause permanent hardware damage to the battery.
The issue affects some older device models that do not properly implement the charging threshold interface.
Remediation
Install update from vendor's website.