CVE-2026-64603: platform/x86: intel-hid: Protect ACPI notify handler against recursion
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026080653-CVE-2026-64603-6444@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda16290 ("ACPI: OSL: Allow Notify () handlers to run on all CPUs") ACPI notify handlers like the intel-hid notify_handler() may run on multiple CPU cores racing with themselves. On convertibles and detachables (matched by DMI chassis-type 31 and 32 in dmi_auto_add_switch[]) the SW_TABLET_MODE input device is registered lazily from notify_handler() on the first tablet-mode event, via intel_hid_switches_setup(). When two such events race on different CPUs both can pass the !priv->switches check and register the priv->switches input device twice, resulting in a duplicate sysfs entry and a subsequent NULL pointer dereference. This is the same class of bug fixed by commit e075c3b13a0a ("platform/x86: intel-vbtn: Protect ACPI notify handler against recursion") for the sibling intel-vbtn driver. Protect intel-hid notify_handler() from racing with itself with a mutex to fix this. The Linux kernel CVE team has assigned CVE-2026-64603 to this issue. Affected and fixed versions =========================== Issue introduced in 6.8 with commit e2ffcda1629012a2c1a3706432bc45fdc899a584 and fixed in 6.12.96 with commit a6402808e552e44e9c26a9fe8395ac11703d5800 Issue introduced in 6.8 with commit e2ffcda1629012a2c1a3706432bc45fdc899a584 and fixed in 6.18.39 with commit 86df6499dfd232fbc1c82c0d6eb9322ca67b8cd0 Issue introduced in 6.8 with commit e2ffcda1629012a2c1a3706432bc45fdc899a584 and fixed in 7.1.4 with commit eace3b3e729d5ba11794d69acfafb58a7950217c Issue introduced in 6.8 with commit e2ffcda1629012a2c1a3706432bc45fdc899a584 and fixed in 7.2-rc1 with commit c085d82613d5618814b84406c8b2d64f1bc305e7 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-64603 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/platform/x86/intel/hid.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/a6402808e552e44e9c26a9fe8395ac11703d5800 https://git.kernel.org/stable/c/86df6499dfd232fbc1c82c0d6eb9322ca67b8cd0 https://git.kernel.org/stable/c/eace3b3e729d5ba11794d69acfafb58a7950217c https://git.kernel.org/stable/c/c085d82613d5618814b84406c8b2d64f1bc305e7