ACPI Vulnerability in Linux Kernel Affects Performance Control Feature
CVE-2026-64512
What is CVE-2026-64512?
An out-of-bounds access vulnerability exists in the Linux kernel's ACPI subsystem, specifically impacting the performance control feature. The reg->access_width field is misused based on the type of reg->space_id, particularly with the ACPI_ADR_SPACE_PLATFORM_COMM. This can trigger a UBSAN (Undefined Behavior Sanitizer) warning when the access_width exceeds the expected limit, resulting in a potential risk during computation involving shift operations. The vulnerability manifests in specific configurations of the kernel, stressing the importance of validating both region type and access_width value to prevent out-of-bounds shifts that jeopardize system stability and security.
Affected Version(s)
Linux 4949affd5288b867cdf115f5b08d6166b2027f87
Linux 01fc53be672acae37e611c80cc0b4f3939584de3
Linux 1b890ae474d19800a6be1696df7fb4d9a41676e4 < 2fb80e962029000959f651665baa4838cc92eb99