{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-97450","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-24T14:53:16.871Z","datePublished":"2026-09-24T16:04:06.092Z","dateUpdated":"2026-10-03T10:58:34.169Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:58:34.169Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nACPICA: validate handler object type in two places\n\nACPICA: validate handler object type in acpi_ev_has_default_handler()\nand acpi_ev_find_region_handler()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The malformed AML that leaves a non-ACPI_TYPE_LOCAL_ADDRESS_HANDLER object as common_notify.handler arrives in a DSDT/SSDT. acpi_ev_find_region_handler() is reached from acpi_ev_install_space_handler() via acpi_install_address_space_handler(ACPI_ROOT_OBJECT) in ec_install_handlers()/acpi_ipmi_init(), and from acpi_ev_initialize_region() during acpi_tb_load_namespace(); no network message carries those bytes.\nAC:L - acpi_ev_install_space_handler() skips the DEVICE/PROCESSOR/THERMAL type check for acpi_gbl_root_node, so CopyObject of a Buffer onto `\\` makes obj_desc->common_notify.handler overlay Buffer.aml_start. A later handler install or OperationRegion init walks address_space.next on every run; the table author sets those objects and no race is required.\nPR:N - acpi_bus_init() calls acpi_load_tables() which executes module-level AML, then acpi_initialize_objects() → acpi_ev_initialize_op_regions() → acpi_ev_has_default_handler(acpi_gbl_root_node), and ec_install_handlers() calls acpi_install_address_space_handler(ACPI_ROOT_OBJECT) with no capable() check; a compromised DSDT/SSDT needs no Linux account.\nUI:N - Module-level AML runs in acpi_ns_execute_table() during acpi_load_tables(), and acpi_ev_find_region_handler() then runs from acpi_ev_initialize_op_regions() and from EC/IPMI/PCC handler install in boot/probe; that is ordinary power-on with no mount or file-open by a victim.\nS:U - The type-confused walk in acpi_ev_find_region_handler()/acpi_ev_has_default_handler() and the stores in acpi_ev_attach_region() stay inside the host ACPICA operand-object heap and do not cross a KVM/Xen, IOMMU, or sandbox boundary.\nC:H - Without the ACPI_TYPE_LOCAL_ADDRESS_HANDLER check, acpi_ev_find_region_handler() reads address_space.space_id and follows address_space.next from a wrong-typed operand (or from AML bytes overlaying common_notify.handler), an unbounded kernel overread of adjacent heap or attacker-chosen addresses rather than a few header bytes.\nI:H - acpi_ev_initialize_region() passes the type-confused pointer from acpi_ev_find_region_handler() to acpi_ev_attach_region(), which writes region_list and handler links through it; a matching fake space_id makes acpi_ev_address_space_dispatch() later invoke address_space.handler as a function pointer, which is type-confusion control-flow hijack.\nA:H - Walking address_space.next from a non-handler object (the ASAN global-buffer-overflow in AcpiEvFindRegionHandler on issue26.aml) dereferences an invalid pointer and oopses or panics the kernel during acpi_ev_install_space_handler() or acpi_ev_initialize_region()."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/acpi/acpica/evhandler.c"],"versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7af2da201623ab5bc0773bd3eeb2f2345cfa1c4a","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9d9fbf6b895a23238e4a7b1a3230f648f0d952a1","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e98825650c2eb1605c707fd1391ceed65bb8e481","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"254e304f68dc079906ce2df4723548ffe35f682a","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"bfd981d35ed3156414fd35b4fe311d5d25cbfca6","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"4c977d57a784682dc8c6cce2f9253ef44ec28ae8","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c5296da2d516707862f8a2dbb4b515f777e5294f","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/acpi/acpica/evhandler.c"],"versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/7af2da201623ab5bc0773bd3eeb2f2345cfa1c4a"},{"url":"https://git.kernel.org/stable/c/9d9fbf6b895a23238e4a7b1a3230f648f0d952a1"},{"url":"https://git.kernel.org/stable/c/e98825650c2eb1605c707fd1391ceed65bb8e481"},{"url":"https://git.kernel.org/stable/c/254e304f68dc079906ce2df4723548ffe35f682a"},{"url":"https://git.kernel.org/stable/c/bfd981d35ed3156414fd35b4fe311d5d25cbfca6"},{"url":"https://git.kernel.org/stable/c/4c977d57a784682dc8c6cce2f9253ef44ec28ae8"},{"url":"https://git.kernel.org/stable/c/c5296da2d516707862f8a2dbb4b515f777e5294f"}],"title":"ACPICA: validate handler object type in two places","x_generator":{"engine":"bippy-1.2.0"}}}}