CVE-2026-64511
CVE CVE-2026-64511EUVD EUVD-2026-48855Published 2026-07-25T08:52:03.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: ACPI: NFIT: core: Fix possible NULL pointer dereference After commit 9b311b7313d6 ("ACPI: NFIT: Install Notify() handler before getting NFIT table"), acpi_nfit_probe() installs an ACPI notify handler for the NFIT device before checking the presence of the NFIT table. If that table is not there, 0 is returned without allocating the acpi_desc object and setting the driver data pointer of the NFIT device. If the platform firmware triggers an NFIT_NOTIFY_UC_MEMORY_ERROR notification on the NFIT device at that point, acpi_nfit_uc_error_notify() will dereference a NULL pointer. Prevent that from occurring by adding an acpi_desc check against NULL to acpi_nfit_uc_error_notify().
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 6.6; patch: 6.12.96; patch: 6.6.145; patch: 6.18.39; 9b311b7313d6c104dd4a2d43ab54536dce07f960 <3c8f73b0fbdf956c98e2329d5aaea3ad09a9cfb6; 9b311b7313d6c104dd4a2d43ab54536dce07f960 <027e128abb82788189d6d45b68e3e8e7329b67be; patch: 7.1.4; 9b311b7313d6c104dd4a2d43ab54536dce07f960 <a44343fe230aa48c74ef09830f3c5c90848b257e; patch: 0; 9b311b7313d6c104dd4a2d43ab54536dce07f960 <873576e585da5d0fc5debbab74eed565c0acea99; patch: 7.2-rc1; 9b311b7313d6c104dd4a2d43ab54536dce07f960 <452945662fd8e9862a2d2043239c7ee1815d1ac4
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.