Executive brief
A vulnerability was identified in the Linux kernel's ACPI Collaborative Processor Performance Control (CPPC) driver. The issue arises from how the system handles specific hardware communication regions, which could lead to an internal error (shift-out-of-bounds) when processing certain hardware configurations. While primarily a stability issue, it could potentially lead to system crashes or unpredictable behavior during power management operations.
Technical details
A shift-out-of-bounds vulnerability exists in drivers/acpi/cppc_acpi.c within the Linux kernel. The root cause is the misuse of the 'access_width' field in ACPI registers; when the 'space_id' is ACPI_ADR_SPACE_PLATFORM_COMM (PCC), the 'access_width' field is repurposed to indicate the PCC subspace ID rather than the actual bit width. If this value exceeds 4, the GET_BIT_WIDTH macro performs an invalid bitwise shift (e.g., 8 << 32), triggering a Undefined Behavior Sanitizer (UBSAN) warning and potential kernel instability. The fix involves validating the region type and ensuring 'access_width' is only decoded for non-PCC registers. Patches have been released for multiple stable kernel branches including 5.15, 6.1, 6.6, 6.8, and 6.9.
Affected products
- Linux Linux Kernel 5.15.154 to 5.15.155, 6.1.90 to 6.1.91, 6.6.32 to 6.6.33, 6.8.11 to 6.8.12, 6.9.2 to 6.9.3
Timeline
- 2026-06-01: disclosed: Initial patch submitted by Jeremy Linton
- 2026-06-08: patched: Mainline kernel patch committed
- 2026-07-25: advisory: CVE published in NVD dataset
References
- https://git.kernel.org/stable/c/1b1acf2dada0cc3931bb2cb9ff8832edfbee46a1
- https://git.kernel.org/stable/c/2fb80e962029000959f651665baa4838cc92eb99
- https://git.kernel.org/stable/c/37f28bf8f14672dfa395994e41fd778a63f0bf5c
- https://git.kernel.org/stable/c/b54c4632946ae42f2b39ed38abd909bbf78cbcc2
- https://git.kernel.org/stable/c/dc066bd13c860bb27d6ace511210e18b8064c1d9
- https://git.kernel.org/stable/c/e904596ba6dd108534ffa15e3e46b2fe245145e2
- https://git.kernel.org/stable/c/f29dc6132d4968e39d8fa575d1a12e2c718ce57b