PT-2026-61330 · Linux+1 · Linux Kernel+1

CVE-2026-64013

·

Published

2026-05-25

·

Updated

2026-09-07

CVSS v2.0

2.9

Low

VectorAV:L/AC:L/Au:M/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the ACPI button driver where the acpi button remove() function fails to correctly update the notify handler type. This occurs because the handler type was changed to ACPI ALL NOTIFY in a previous commit, but the removal process was not updated to match. This results in a leak of the ACPI General Purpose Event (GPE) handler after the driver is removed. If an ACPI notify event is triggered on the device after driver removal, it may lead to a kernel crash or cause subsequent attempts to probe the device with the same driver to fail.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14316
CVE-2026-64013
USN-8593-1
USN-8603-1
USN-8618-1
USN-8663-1
USN-8664-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu