CVE-2026-64511

Unknown

Last modified

CVE-2026-64511 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: ACPI: NFIT: core: Fix possible NULL pointer dereference After commit 9b311b7313d6 ("ACPI: NFIT: Install Notify() handler before getting NFIT table"), acpi_nfit_probe() installs an ACPI notify handler for the NFIT device before checking the presence of the NFIT table. If that table is not there, 0 is returned without allocating the acpi_desc object and setting the driver data pointer of the NFIT device.

Description

In the Linux kernel, the following vulnerability has been resolved: ACPI: NFIT: core: Fix possible NULL pointer dereference After commit 9b311b7313d6 ("ACPI: NFIT: Install Notify() handler before getting NFIT table"), acpi_nfit_probe() installs an ACPI notify handler for the NFIT device before checking the presence of the NFIT table. If that table is not there, 0 is returned without allocating the acpi_desc object and setting the driver data pointer of the NFIT device. If the platform firmware triggers an NFIT_NOTIFY_UC_MEMORY_ERROR notification on the NFIT device at that point, acpi_nfit_uc_error_notify() will dereference a NULL pointer. Prevent that from occurring by adding an acpi_desc check against NULL to acpi_nfit_uc_error_notify().

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 9b311b7313d6c104dd4a2d43ab54536dce07f960, < a44343fe230aa48c74ef09830f3c5c90848b257e; >= 9b311b7313d6c104dd4a2d43ab54536dce07f960, < 3c8f73b0fbdf956c98e2329d5aaea3ad09a9cfb6; >= 9b311b7313d6c104dd4a2d43ab54536dce07f960, < 452945662fd8e9862a2d2043239c7ee1815d1ac4; >= 9b311b7313d6c104dd4a2d43ab54536dce07f960, < 873576e585da5d0fc5debbab74eed565c0acea99; >= 9b311b7313d6c104dd4a2d43ab54536dce07f960, < 027e128abb82788189d6d45b68e3e8e7329b67be
LinuxLinux6.6

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-64511?
In the Linux kernel, the following vulnerability has been resolved: ACPI: NFIT: core: Fix possible NULL pointer dereference After commit 9b311b7313d6 ("ACPI: NFIT: Install Notify() handler before getting NFIT table"), acpi_nfit_probe() installs an ACPI notify handler for the NFIT device before checking the presence of the NFIT table. If that table is not there, 0 is returned without allocating the acpi_desc object and setting the driver data pointer of the NFIT device. If the platform firmware triggers an NFIT_NOTIFY_UC_MEMORY_ERROR notification on the NFIT device at that point, acpi_nfit_uc_error_notify() will dereference a NULL pointer. Prevent that from occurring by adding an acpi_desc check against NULL to acpi_nfit_uc_error_notify().
How severe is CVE-2026-64511?
Severity scoring for CVE-2026-64511 is pending analysis.
How do I fix CVE-2026-64511?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-64511?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST