CVE-2026-64512: ACPI: CPPC: Suppress UBSAN warning caused by field misuse

Greg Kroah-Hartman <[email protected]> Sat, 25 Jul 2026 10:52:09 +0200
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026072555-CVE-2026-64512-01fe@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

ACPI: CPPC: Suppress UBSAN warning caused by field misuse

The definition of reg->access_width changes depending on the
reg->space_id type.  Type ACPI_ADR_SPACE_PLATFORM_COMM uses
access_width to indicate the PCC region, which can result in a UBSAN
if the value is greater than 4.

For example:

 UBSAN: shift-out-of-bounds in drivers/acpi/cppc_acpi.c:1090:9
 shift exponent 32 is too large for 32-bit type 'int'
 CPU: 61 UID: 0 PID: 1220 Comm: (udev-worker) Not tainted 7.0.10-201.fc44.aarch64 #1 PREEMPT(lazy)
 Hardware name: To be filled by O.E.M.
 Call trace:
  ...(trimming)
  ubsan_epilogue+0x10/0x48
  __ubsan_handle_shift_out_of_bounds+0xdc/0x1e0
  cpc_write+0x4d0/0x670
  cppc_set_perf+0x18c/0x490
  cppc_cpufreq_cpu_init+0x1c8/0x380 [cppc_cpufreq]
  ... (trimming)

Lets fix this by validating the region type, as well as whether
access_width has a value. Then since we are returning bit_width
directly for ACPI_ADR_SPACE_PLATFORM_COMM, drop the code correcting
the size.

The Linux kernel CVE team has assigned CVE-2026-64512 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.15.154 with commit 4949affd5288b867cdf115f5b08d6166b2027f87 and fixed in 5.15.155 with commit b54c4632946ae42f2b39ed38abd909bbf78cbcc2
	Issue introduced in 6.1.90 with commit 01fc53be672acae37e611c80cc0b4f3939584de3 and fixed in 6.1.178 with commit e904596ba6dd108534ffa15e3e46b2fe245145e2
	Issue introduced in 6.6.30 with commit 1b890ae474d19800a6be1696df7fb4d9a41676e4 and fixed in 6.6.145 with commit 2fb80e962029000959f651665baa4838cc92eb99
	Issue introduced in 6.9 with commit 2f4a4d63a193be6fd530d180bb13c3592052904c and fixed in 6.12.96 with commit 37f28bf8f14672dfa395994e41fd778a63f0bf5c
	Issue introduced in 6.9 with commit 2f4a4d63a193be6fd530d180bb13c3592052904c and fixed in 6.18.39 with commit f29dc6132d4968e39d8fa575d1a12e2c718ce57b
	Issue introduced in 6.9 with commit 2f4a4d63a193be6fd530d180bb13c3592052904c and fixed in 7.1.4 with commit dc066bd13c860bb27d6ace511210e18b8064c1d9
	Issue introduced in 6.9 with commit 2f4a4d63a193be6fd530d180bb13c3592052904c and fixed in 7.2-rc1 with commit 1b1acf2dada0cc3931bb2cb9ff8832edfbee46a1
	Issue introduced in 6.8.9 with commit 6cb6b12b78dcd8867a3fdbb1b6d0ed1df2b208d1

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64512
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/acpi/cppc_acpi.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/b54c4632946ae42f2b39ed38abd909bbf78cbcc2
	https://git.kernel.org/stable/c/e904596ba6dd108534ffa15e3e46b2fe245145e2
	https://git.kernel.org/stable/c/2fb80e962029000959f651665baa4838cc92eb99
	https://git.kernel.org/stable/c/37f28bf8f14672dfa395994e41fd778a63f0bf5c
	https://git.kernel.org/stable/c/f29dc6132d4968e39d8fa575d1a12e2c718ce57b
	https://git.kernel.org/stable/c/dc066bd13c860bb27d6ace511210e18b8064c1d9
	https://git.kernel.org/stable/c/1b1acf2dada0cc3931bb2cb9ff8832edfbee46a1