CVE-2026-93124

Source
https://cve.org/CVERecord?id=CVE-2026-93124
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93124.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93124
Downstream
Published
2026-09-17T16:11:29Z
Modified
2026-09-18T03:48:44Z
Summary
platform/x86: asus-wireless: Fail probe when there is no ACPI match
Details

In the Linux kernel, the following vulnerability has been resolved:

platform/x86: asus-wireless: Fail probe when there is no ACPI match

Every platform driver can be forced to match a device that does not match its list of device IDs because of device_match_driver_override(), so platform drivers that rely on the existence of a device ACPI companion object need to verify its presence.

asus_wireless_probe() returns success when acpi_match_acpi_device() finds no match, leaving behind an input device that never reports anything because the notify handler is not installed. Worse, when the driver is force-bound to a device without an ACPI companion, probe still succeeds and stores a NULL companion pointer, which asus_wireless_remove() later passes to acpi_dev_remove_notify_handler(), leading to a NULL pointer dereference on unbind.

Return -ENODEV when the device does not match the ID table. This also covers the missing-companion case, because acpi_match_acpi_device() rejects a NULL device. Perform the check before allocating any driver state, instead of after the input device has already been registered.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93124.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f7e648027d7e1b5c06eb86d944b7e23926254cee
Fixed
7bfa711f311a584002e16ecd750627306deb805c
Fixed
4aefd66ef7822cf7d3f53146dcee0b71021ed2b7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93124.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.1.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93124.json"