CVE-2026-93114

Source
https://cve.org/CVERecord?id=CVE-2026-93114
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93114.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93114
Downstream
Published
2026-09-17T16:11:22Z
Modified
2026-09-19T03:47:31Z
Summary
platform/surface: acpi-notify: Check ACPI companion before use
Details

In the Linux kernel, the following vulnerability has been resolved:

platform/surface: acpi-notify: Check ACPI companion before use

Since every platform driver can be forced to match a device that doesn't match its list of device IDs because of device_match_driver_override(), platform drivers that rely on the existence of a device's ACPI companion object should verify its presence.

san_probe() dereferences the result of ACPI_COMPANION() when installing the GSBUS address space handler, so force-binding the driver to a device without an ACPI companion leads to a NULL pointer dereference. The dereference was introduced when the probe function was switched from ACPI_HANDLE() to ACPI_COMPANION().

Check the ACPI companion against NULL and return -ENODEV when it is missing, like commit e4865a56d013 ("ACPI: driver: Check ACPI_COMPANION() against NULL during probe") does for the core ACPI platform drivers.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93114.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a9e10e58730432e5de840eb3ddd55c75f29341b3
Fixed
4faa43d4ef0b98beb6c2b77a279f4aa5d7fa2d13
Fixed
3855be0100efb98c26228c610db70a673611f3bd
Fixed
f276b62f2ce1cbff7fa50a8ee5afd8fef5a60897
Fixed
9b6479da662c2ec4e931ed9f7228df46aa8c3766
Fixed
7fea5a310e3b2db24f7aafe64897e4e659ffbb7d
Fixed
428a82d987fcd8844e8868c85582eae75b4b5c51
Fixed
2b3a5dabe89e330413af403246b648c1890f368f

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93114.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.14.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93114.json"