Vulnerability in Linux Kernel Affects EFI Runtime Calls
CVE-2026-64183

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-64183?

A vulnerability has been identified in the Linux kernel related to the allocation of a runtime workqueue before ACPI initialization. The problem arises when ACPI PRM calls are processed before the necessary initialization is completed, which can lead to NULL pointer dereferences and potential faults. This issue highlights the importance of proper initialization ordering and the need for careful handling of EFI runtime calls in connection with firmware accesses. The kernel maintains stability by ensuring that these runtime calls are accessible across the relevant initialization phases.

Affected Version(s)

Linux 5894cf571e14fb393a4d0a82538de032127b9d8b < 29cd94e678fcb3c4fd0f359deeac6d61334323fc

Linux 5894cf571e14fb393a4d0a82538de032127b9d8b < 6996e954ae830f5b793ba6cf449885ca519dbdd2

Linux 5894cf571e14fb393a4d0a82538de032127b9d8b

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.