SB2026072744 - Improper input validation in Linux kernel acpi driver
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper input validation (CVE-ID: CVE-2026-64512)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the ACPI CPPC register width handling in drivers/acpi/cppc_acpi.c when processing ACPI PCC register definitions. A local attacker can provide a crafted access_width value to trigger a shift-out-of-bounds condition and cause a denial of service.
The issue occurs because the access_width field is reused as a PCC subspace identifier for ACPI_ADR_SPACE_PLATFORM_COMM entries.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1b1acf2dada0cc3931bb2cb9ff8832edfbee46a1
- https://git.kernel.org/stable/c/2fb80e962029000959f651665baa4838cc92eb99
- https://git.kernel.org/stable/c/37f28bf8f14672dfa395994e41fd778a63f0bf5c
- https://git.kernel.org/stable/c/b54c4632946ae42f2b39ed38abd909bbf78cbcc2
- https://git.kernel.org/stable/c/dc066bd13c860bb27d6ace511210e18b8064c1d9
- https://git.kernel.org/stable/c/e904596ba6dd108534ffa15e3e46b2fe245145e2
- https://git.kernel.org/stable/c/f29dc6132d4968e39d8fa575d1a12e2c718ce57b