Linux Kernel Vulnerability in ACPI's NFIT Device Handler
CVE-2026-64511

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 July 2026

What is CVE-2026-64511?

A vulnerability in the Linux kernel's implementation of the ACPI NFIT device handler can lead to a NULL pointer dereference when the corresponding NFIT table is absent. This occurs if the platform's firmware triggers a notification for uncorrectable memory errors before validating the presence of the necessary NFIT table. To mitigate this issue, a check against NULL was added to prevent potential crashes or unintended behavior caused by dereferencing a NULL pointer.

Affected Version(s)

Linux 9b311b7313d6c104dd4a2d43ab54536dce07f960

Linux 9b311b7313d6c104dd4a2d43ab54536dce07f960 < 3c8f73b0fbdf956c98e2329d5aaea3ad09a9cfb6

Linux 9b311b7313d6c104dd4a2d43ab54536dce07f960 < 452945662fd8e9862a2d2043239c7ee1815d1ac4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.