---
cve: "CVE-2026-64603"
severity: "LOW"
cvss: 3.1
epss: "16%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-08-06 08:16:36"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-15T19:19:23+02:00"
---

# CVE-2026-64603

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

platform/x86: intel-hid: Protect ACPI notify handler against recursion

Since commit e2ffcda16290 ("ACPI: OSL: Allow Notify () handlers to run on
all CPUs") ACPI notify handlers like the intel-hid notify_handler() may
run on multiple CPU cores racing with themselves.

On convertibles and detachables (matched by DMI chassis-type 31 and 32 in
dmi_auto_add_switch[]) the SW_TABLET_MODE input device is registered
lazily from notify_handler() on the first tablet-mode event, via
intel_hid_switches_setup(). When two such events race on different CPUs
both can pass the !priv->switches check and register the priv->switches
input device twice, resulting in a duplicate sysfs entry and a subsequent
NULL pointer dereference.

This is the same class of bug fixed by commit e075c3b13a0a ("platform/x86:
intel-vbtn: Protect ACPI notify handler against recursion") for the
sibling intel-vbtn driver.

Protect intel-hid notify_handler() from racing with itself with a mutex
to fix this.

## Patch verfügbar (OSV)

- Kernel ≥ 6.12.96
- Kernel ≥ 6.18.39
- Kernel ≥ 7.1.4

## Referenzen

- <https://git.kernel.org/stable/c/a6402808e552e44e9c26a9fe8395ac11703d5800>
- <https://git.kernel.org/stable/c/86df6499dfd232fbc1c82c0d6eb9322ca67b8cd0>
- <https://git.kernel.org/stable/c/eace3b3e729d5ba11794d69acfafb58a7950217c>
- <https://git.kernel.org/stable/c/c085d82613d5618814b84406c8b2d64f1bc305e7>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-64603) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
