CVE-2026-93128

Source
https://cve.org/CVERecord?id=CVE-2026-93128
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93128.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93128
Downstream
Published
2026-09-17T16:11:31Z
Modified
2026-09-18T03:48:44Z
Summary
platform/x86: lg-laptop: Fix LED resource handling
Details

In the Linux kernel, the following vulnerability has been resolved:

platform/x86: lg-laptop: Fix LED resource handling

The event notification callback might access kbd_backlight even when it was not successfully registered with the LED subsystem. The same happens inside acpi_remove(), where the LED devices are unregistered unconditionally.

Fix this by tracking the availability of the kbd_backlight LED device and use devm_led_classdev_register() to let devres take care of unregistering the LED devices during removal. For this the parent device of the LED devices is changed to the native platform device.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93128.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ae26278829a80ad0e60ff004de71e9276cee5dc0
Fixed
4fbfe3714f645b6c64c9ba8faa83b27e4c9f2edd
Fixed
9a85e2d35e54248aca39bad4f4152ed34de1995f
Fixed
acc190322250562d5f28860f4ae1ebaf3e304fc2
Fixed
3e91964aa74ab261aa15d9d96318eded2fd9d22a

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93128.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93128.json"