CVE-2026-64511 PUBLISHED

ACPI: NFIT: core: Fix possible NULL pointer dereference

Assigner: Linux
Reserved: 19.07.2026 Published: 25.07.2026 Updated: 25.07.2026

In the Linux kernel, the following vulnerability has been resolved:

ACPI: NFIT: core: Fix possible NULL pointer dereference

After commit 9b311b7313d6 ("ACPI: NFIT: Install Notify() handler before getting NFIT table"), acpi_nfit_probe() installs an ACPI notify handler for the NFIT device before checking the presence of the NFIT table. If that table is not there, 0 is returned without allocating the acpi_desc object and setting the driver data pointer of the NFIT device. If the platform firmware triggers an NFIT_NOTIFY_UC_MEMORY_ERROR notification on the NFIT device at that point, acpi_nfit_uc_error_notify() will dereference a NULL pointer.

Prevent that from occurring by adding an acpi_desc check against NULL to acpi_nfit_uc_error_notify().

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 9b311b7313d6c104dd4a2d43ab54536dce07f960 to a44343fe230aa48c74ef09830f3c5c90848b257e (excl.)
  • affected from 9b311b7313d6c104dd4a2d43ab54536dce07f960 to 3c8f73b0fbdf956c98e2329d5aaea3ad09a9cfb6 (excl.)
  • affected from 9b311b7313d6c104dd4a2d43ab54536dce07f960 to 452945662fd8e9862a2d2043239c7ee1815d1ac4 (excl.)
  • affected from 9b311b7313d6c104dd4a2d43ab54536dce07f960 to 873576e585da5d0fc5debbab74eed565c0acea99 (excl.)
  • affected from 9b311b7313d6c104dd4a2d43ab54536dce07f960 to 027e128abb82788189d6d45b68e3e8e7329b67be (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.6 is affected
  • unaffected from 0 to 6.6 (excl.)
  • unaffected from 6.6.145 to 6.6.* (incl.)
  • unaffected from 6.12.96 to 6.12.* (incl.)
  • unaffected from 6.18.39 to 6.18.* (incl.)
  • unaffected from 7.1.4 to 7.1.* (incl.)
  • unaffected from 7.2-rc1 to * (incl.)

References