CVE-2026-64013

Source
https://cve.org/CVERecord?id=CVE-2026-64013
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64013.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64013
Downstream
Published
2026-07-19T14:56:27.365Z
Modified
2026-07-21T03:47:47.623163575Z
Summary
ACPI: button: Fix ACPI GPE handler leak during removal
Details

In the Linux kernel, the following vulnerability has been resolved:

ACPI: button: Fix ACPI GPE handler leak during removal

Commit a7e23ec17fee ("ACPI: button: Install notifier for system events as well") changed the ACPI notify handler type for ACPI buttons to ACPIALLNOTIFY, but it forgot to update acpibuttonremove() to reflect that change. This leads to leaking the notify handler past driver removal, which may cause a kernel crash to occur if ACPI notify on the given device is triggered after removing the driver, and causes a subsequent probe of the given device with the same driver to fail.

Address this by updating the acpiremovenotifyhandler() call in acpibutton_remove() as appropriate.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64013.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a7e23ec17feecc7bac0d500cea900cace7b50129
Fixed
614cb8c26c5aa53196ee9b211b76ee618b147d32
Fixed
fe80251152fed5b185f795ef2cd9f7fe9c3162e0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64013.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.15.0
Fixed
7.0.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64013.json"