CVE-2026-64227
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
24/07/2026
Last modified:
13/08/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ACPI: driver: Check ACPI_COMPANION() against NULL during probe<br />
<br />
Since every platform driver can be forced to match a device that doesn&#39;t<br />
match its list of device IDs because of device_match_driver_override(),<br />
platform drivers that rely on the existence of a device&#39;s ACPI companion<br />
object should verify its presence.<br />
<br />
Accordingly, add requisite ACPI_COMPANION() or ACPI_HANDLE() checks<br />
against NULL to 13 platform drivers handling core ACPI devices.<br />
<br />
Also change the value returned by the ACPI thermal zone driver when<br />
the device&#39;s ACPI companion is not present to -ENODEV for consistency<br />
with the other drivers.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.97 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.40 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.11 (excluding) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



