NULL pointer dereference in Linux kernel - CVE-2026-64183
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in the EFI runtime workqueue handling for ACPI PRM calls when invoking EFI runtime calls during early initialization. A local user can trigger early PRM-related runtime calls to cause a denial of service.
The issue occurs when ACPI PRM accesses happen before the EFI runtime workqueue has been allocated during system initialization.
How to mitigate CVE-2026-64183
Sources
- https://git.kernel.org/stable/c/13c6da02e767152c9ac4330962247a5e47011035
- https://git.kernel.org/stable/c/29cd94e678fcb3c4fd0f359deeac6d61334323fc
- https://git.kernel.org/stable/c/6996e954ae830f5b793ba6cf449885ca519dbdd2
- https://git.kernel.org/stable/c/c32a1fbe0f9a48453a552bb315cc4f1e7a74084e
- https://git.kernel.org/stable/c/e871549f7894ad4114b3dd53f241aa25a268ba8b