CVE-2026-64603: platform/x86: intel-hid: Protect ACPI notify handler against recursion

Greg Kroah-Hartman <[email protected]>
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026080653-CVE-2026-64603-6444@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

platform/x86: intel-hid: Protect ACPI notify handler against recursion

Since commit e2ffcda16290 ("ACPI: OSL: Allow Notify () handlers to run on
all CPUs") ACPI notify handlers like the intel-hid notify_handler() may
run on multiple CPU cores racing with themselves.

On convertibles and detachables (matched by DMI chassis-type 31 and 32 in
dmi_auto_add_switch[]) the SW_TABLET_MODE input device is registered
lazily from notify_handler() on the first tablet-mode event, via
intel_hid_switches_setup(). When two such events race on different CPUs
both can pass the !priv->switches check and register the priv->switches
input device twice, resulting in a duplicate sysfs entry and a subsequent
NULL pointer dereference.

This is the same class of bug fixed by commit e075c3b13a0a ("platform/x86:
intel-vbtn: Protect ACPI notify handler against recursion") for the
sibling intel-vbtn driver.

Protect intel-hid notify_handler() from racing with itself with a mutex
to fix this.

The Linux kernel CVE team has assigned CVE-2026-64603 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 6.8 with commit e2ffcda1629012a2c1a3706432bc45fdc899a584 and fixed in 6.12.96 with commit a6402808e552e44e9c26a9fe8395ac11703d5800
	Issue introduced in 6.8 with commit e2ffcda1629012a2c1a3706432bc45fdc899a584 and fixed in 6.18.39 with commit 86df6499dfd232fbc1c82c0d6eb9322ca67b8cd0
	Issue introduced in 6.8 with commit e2ffcda1629012a2c1a3706432bc45fdc899a584 and fixed in 7.1.4 with commit eace3b3e729d5ba11794d69acfafb58a7950217c
	Issue introduced in 6.8 with commit e2ffcda1629012a2c1a3706432bc45fdc899a584 and fixed in 7.2-rc1 with commit c085d82613d5618814b84406c8b2d64f1bc305e7

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64603
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/platform/x86/intel/hid.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/a6402808e552e44e9c26a9fe8395ac11703d5800
	https://git.kernel.org/stable/c/86df6499dfd232fbc1c82c0d6eb9322ca67b8cd0
	https://git.kernel.org/stable/c/eace3b3e729d5ba11794d69acfafb58a7950217c
	https://git.kernel.org/stable/c/c085d82613d5618814b84406c8b2d64f1bc305e7
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.