Vulnerability in Linux Kernel Affects Intel HID Notify Handlers
CVE-2026-64603
Currently unrated
What is CVE-2026-64603?
A race condition vulnerability exists in the Intel HID notify handler of the Linux kernel. This flaw occurs when ACPI notify handlers are executed on multiple CPU cores simultaneously, potentially resulting in a duplicate input device registration. Specifically, when multiple tablet-mode events are triggered, the handlers can race against each other, leading to a NULL pointer dereference due to duplicate sysfs entries. This vulnerability has been addressed by implementing mutex protection within the notify handler to prevent recursive calls.
Affected Version(s)
Linux e2ffcda1629012a2c1a3706432bc45fdc899a584
Linux e2ffcda1629012a2c1a3706432bc45fdc899a584 < 86df6499dfd232fbc1c82c0d6eb9322ca67b8cd0
Linux e2ffcda1629012a2c1a3706432bc45fdc899a584