CVE-2026-97450
8.4Linux · Kernel
A vulnerability in the Linux kernel ACPICA subsystem allows potential memory corruption or unauthorized access due to improper validation of handler object types in specific handler functions.
Executive summary
The Linux kernel is affected by an input validation vulnerability in the ACPICA subsystem that could lead to full system compromise.
Vulnerability
This flaw stems from missing validation of handler object types within the acpi_ev_has_default_handler and acpi_ev_find_region_handler functions. An attacker can leverage this oversight to trigger unexpected behavior in the kernel, potentially leading to unauthorized data access or system instability.
Business impact
The identified vulnerability carries a CVSS score of 8.4, reflecting a high severity risk. Successful exploitation could allow an attacker to gain elevated privileges or perform unauthorized operations within the kernel, leading to total system compromise, data theft, or prolonged service disruption.
Remediation
Immediate Action: Update the Linux kernel to version 6.12.111, 6.18.53, or a later stable release as soon as possible.
Proactive Monitoring: Monitor system logs for kernel panics, segmentation faults, or unusual hardware-related error messages that may indicate exploitation attempts.
Compensating Controls: Ensure that access to the system is strictly limited to authorized users and implement kernel hardening features to restrict the execution of untrusted code.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the critical nature of the Linux kernel, this vulnerability represents a significant risk to system integrity. Administrators should prioritize the deployment of the provided kernel patches across all affected environments to eliminate the risk of exploitation.
More Linux CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section