Use-after-free in Linux kernel - CVE-2026-64510
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to use-after-free in the ACPI NFIT core when handling a subsequent ACPI Machine Check Exception after a failed or incomplete NFIT initialization and shutdown path. A local attacker can trigger the vulnerable initialization state to cause a denial of service.
The issue occurs because a freed acpi_desc object may remain referenced in the acpi_descs list and later be accessed by nfit_handle_mce().
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-64510
linux (Debian package) - update to 6.12.100-1
External References
- https://git.kernel.org/stable/c/38bf27511ef41bffebd157ec3eba41fc89ba59cd
- https://git.kernel.org/stable/c/3b2628f7682aea8d9ce09ad4b9a3bd144b451eaa
- https://git.kernel.org/stable/c/6ff054cc02a763914773b026cacb429e5fbf64fa
- https://git.kernel.org/stable/c/7d69235bdc581a4346e9bcd6a8bea37d3e1abd25
- https://git.kernel.org/stable/c/b07d22a2d17ad6465c87bd5752bc70e4c16e0ee4
- https://git.kernel.org/stable/c/c127dbd832bd4b9aef8a749d9f491b74042f9b47
- https://git.kernel.org/stable/c/df7c92216a1583a76cb0cbf2f21cd68870609b05
- https://git.kernel.org/stable/c/ee82078e776ae31266cc70fdf62ac17c3c6f100a