0.0
NA
CVE-2026-64512
ACPI: CPPC: Suppress UBSAN warning caused by field misuse
Description

In the Linux kernel, the following vulnerability has been resolved: ACPI: CPPC: Suppress UBSAN warning caused by field misuse The definition of reg->access_width changes depending on the reg->space_id type. Type ACPI_ADR_SPACE_PLATFORM_COMM uses access_width to indicate the PCC region, which can result in a UBSAN if the value is greater than 4. For example: UBSAN: shift-out-of-bounds in drivers/acpi/cppc_acpi.c:1090:9 shift exponent 32 is too large for 32-bit type 'int' CPU: 61 UID: 0 PID: 1220 Comm: (udev-worker) Not tainted 7.0.10-201.fc44.aarch64 #1 PREEMPT(lazy) Hardware name: To be filled by O.E.M. Call trace: ...(trimming) ubsan_epilogue+0x10/0x48 __ubsan_handle_shift_out_of_bounds+0xdc/0x1e0 cpc_write+0x4d0/0x670 cppc_set_perf+0x18c/0x490 cppc_cpufreq_cpu_init+0x1c8/0x380 [cppc_cpufreq] ... (trimming) Lets fix this by validating the region type, as well as whether access_width has a value. Then since we are returning bit_width directly for ACPI_ADR_SPACE_PLATFORM_COMM, drop the code correcting the size.

INFO

Published Date :

July 25, 2026, 10:17 a.m.

Last Modified :

July 25, 2026, 10:17 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-64512 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

Solution
Address UBSAN warning by validating region type and access_width.
  • Validate region type and access_width.
  • Drop incorrect size correction code.
  • Apply kernel patches.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-64512 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-64512 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-64512 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-64512 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jul. 25, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4949affd5288b867cdf115f5b08d6166b2027f87', 'lessThan': 'b54c4632946ae42f2b39ed38abd909bbf78cbcc2', 'versionType': 'git'}, {'status': 'affected', 'version': '01fc53be672acae37e611c80cc0b4f3939584de3', 'lessThan': 'e904596ba6dd108534ffa15e3e46b2fe245145e2', 'versionType': 'git'}, {'status': 'affected', 'version': '1b890ae474d19800a6be1696df7fb4d9a41676e4', 'lessThan': '2fb80e962029000959f651665baa4838cc92eb99', 'versionType': 'git'}, {'status': 'affected', 'version': '2f4a4d63a193be6fd530d180bb13c3592052904c', 'lessThan': '37f28bf8f14672dfa395994e41fd778a63f0bf5c', 'versionType': 'git'}, {'status': 'affected', 'version': '2f4a4d63a193be6fd530d180bb13c3592052904c', 'lessThan': 'f29dc6132d4968e39d8fa575d1a12e2c718ce57b', 'versionType': 'git'}, {'status': 'affected', 'version': '2f4a4d63a193be6fd530d180bb13c3592052904c', 'lessThan': 'dc066bd13c860bb27d6ace511210e18b8064c1d9', 'versionType': 'git'}, {'status': 'affected', 'version': '2f4a4d63a193be6fd530d180bb13c3592052904c', 'lessThan': '1b1acf2dada0cc3931bb2cb9ff8832edfbee46a1', 'versionType': 'git'}, {'status': 'affected', 'version': '6cb6b12b78dcd8867a3fdbb1b6d0ed1df2b208d1', 'versionType': 'git'}, {'status': 'affected', 'version': '5.15.154', 'lessThan': '5.15.155', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.1.90', 'lessThan': '6.1.178', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.6.30', 'lessThan': '6.6.145', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.8.9', 'lessThan': '6.9', 'versionType': 'semver'}], 'programFiles': ['drivers/acpi/cppc_acpi.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.9'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.9', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.15.155', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.96', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.39', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.4', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/acpi/cppc_acpi.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: ACPI: CPPC: Suppress UBSAN warning caused by field misuse The definition of reg->access_width changes depending on the reg->space_id type. Type ACPI_ADR_SPACE_PLATFORM_COMM uses access_width to indicate the PCC region, which can result in a UBSAN if the value is greater than 4. For example: UBSAN: shift-out-of-bounds in drivers/acpi/cppc_acpi.c:1090:9 shift exponent 32 is too large for 32-bit type 'int' CPU: 61 UID: 0 PID: 1220 Comm: (udev-worker) Not tainted 7.0.10-201.fc44.aarch64 #1 PREEMPT(lazy) Hardware name: To be filled by O.E.M. Call trace: ...(trimming) ubsan_epilogue+0x10/0x48 __ubsan_handle_shift_out_of_bounds+0xdc/0x1e0 cpc_write+0x4d0/0x670 cppc_set_perf+0x18c/0x490 cppc_cpufreq_cpu_init+0x1c8/0x380 [cppc_cpufreq] ... (trimming) Lets fix this by validating the region type, as well as whether access_width has a value. Then since we are returning bit_width directly for ACPI_ADR_SPACE_PLATFORM_COMM, drop the code correcting the size.
    Added Reference https://git.kernel.org/stable/c/1b1acf2dada0cc3931bb2cb9ff8832edfbee46a1
    Added Reference https://git.kernel.org/stable/c/2fb80e962029000959f651665baa4838cc92eb99
    Added Reference https://git.kernel.org/stable/c/37f28bf8f14672dfa395994e41fd778a63f0bf5c
    Added Reference https://git.kernel.org/stable/c/b54c4632946ae42f2b39ed38abd909bbf78cbcc2
    Added Reference https://git.kernel.org/stable/c/dc066bd13c860bb27d6ace511210e18b8064c1d9
    Added Reference https://git.kernel.org/stable/c/e904596ba6dd108534ffa15e3e46b2fe245145e2
    Added Reference https://git.kernel.org/stable/c/f29dc6132d4968e39d8fa575d1a12e2c718ce57b
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.