{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.96-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.4-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux-6.12"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.100-1~deb12u1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  platform/x86: intel-hid: Protect ACPI notify handler against recursion  Since commit e2ffcda16290 (\"ACPI: OSL: Allow Notify () handlers to run on all CPUs\") ACPI notify handlers like the intel-hid notify_handler() may run on multiple CPU cores racing with themselves.  On convertibles and detachables (matched by DMI chassis-type 31 and 32 in dmi_auto_add_switch[]) the SW_TABLET_MODE input device is registered lazily from notify_handler() on the first tablet-mode event, via intel_hid_switches_setup(). When two such events race on different CPUs both can pass the !priv-\u003eswitches check and register the priv-\u003eswitches input device twice, resulting in a duplicate sysfs entry and a subsequent NULL pointer dereference.  This is the same class of bug fixed by commit e075c3b13a0a (\"platform/x86: intel-vbtn: Protect ACPI notify handler against recursion\") for the sibling intel-vbtn driver.  Protect intel-hid notify_handler() from racing with itself with a mutex to fix this.",
  "id": "DEBIAN-CVE-2026-64603",
  "modified": "2026-09-14T16:47:31.892533966Z",
  "published": "2026-08-06T08:16:36.083Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-64603"
    }
  ],
  "upstream": [
    "CVE-2026-64603"
  ]
}