CVE-2026-64603

Source
https://cve.org/CVERecord?id=CVE-2026-64603
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64603.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64603
Downstream
Published
2026-08-06T07:13:55.114Z
Modified
2026-08-08T03:48:19.018079161Z
Summary
platform/x86: intel-hid: Protect ACPI notify handler against recursion
Details

In the Linux kernel, the following vulnerability has been resolved:

platform/x86: intel-hid: Protect ACPI notify handler against recursion

Since commit e2ffcda16290 ("ACPI: OSL: Allow Notify () handlers to run on all CPUs") ACPI notify handlers like the intel-hid notify_handler() may run on multiple CPU cores racing with themselves.

On convertibles and detachables (matched by DMI chassis-type 31 and 32 in dmiautoaddswitch[]) the SWTABLETMODE input device is registered lazily from notifyhandler() on the first tablet-mode event, via intelhidswitches_setup(). When two such events race on different CPUs both can pass the !priv->switches check and register the priv->switches input device twice, resulting in a duplicate sysfs entry and a subsequent NULL pointer dereference.

This is the same class of bug fixed by commit e075c3b13a0a ("platform/x86: intel-vbtn: Protect ACPI notify handler against recursion") for the sibling intel-vbtn driver.

Protect intel-hid notify_handler() from racing with itself with a mutex to fix this.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64603.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e2ffcda1629012a2c1a3706432bc45fdc899a584
Fixed
a6402808e552e44e9c26a9fe8395ac11703d5800
Fixed
86df6499dfd232fbc1c82c0d6eb9322ca67b8cd0
Fixed
eace3b3e729d5ba11794d69acfafb58a7950217c
Fixed
c085d82613d5618814b84406c8b2d64f1bc305e7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64603.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.8.0
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64603.json"