CVE-2026-98202

Source
https://cve.org/CVERecord?id=CVE-2026-98202
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98202.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98202
Downstream
Published
2026-10-06T08:44:40Z
Modified
2026-10-07T02:47:29Z
Summary
Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound
Details

In the Linux kernel, the following vulnerability has been resolved:

Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound

Transport drivers (such as rmi_i2c and rmi_spi) invoke rmi_driver_suspend() and rmi_driver_resume() on their child rmi_dev device during system power management events. However, transport drivers are fully registered and operational even if the physical RMI driver failed to bind or probe the rmi_dev device.

When rmi_driver_suspend() or rmi_driver_resume() is called on an unbound rmi_dev, dev_get_drvdata() returns NULL. Calling rmi_disable_irq() or rmi_enable_irq() without driver data attached causes a NULL pointer dereference and General Protection Fault when attempting to lock data->enabled_mutex.

Fix this by checking if driver data is attached to rmi_dev in rmi_driver_suspend() and rmi_driver_resume(), exiting early if no driver data is present.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98202.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
2b6a321da9a2d8725a1d3dbb0b2e96a7618ebe56
Fixed
7a3d7c68aa36f68e2a4824da4782c0e5d7c4eba4
Fixed
fafca210631d8c2d4311bdfccc5ec46b9fe65977
Fixed
84145a4a1dc58f8959811913c5f61f3235dd9f6c
Fixed
e2b6703465c1ce43edb91c1626604b7092b3c431
Fixed
30366f507ce3e408caf7f7375bb343df54b9a4f9
Fixed
fa1713dc3d43d028d6cb66e5659d9d7e83b73362
Fixed
942b06a19252908d0f952c0590caf20e47f88252
Fixed
fe10579b6dc3f0dac61e51e1797cacbba5039ac2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98202.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.6.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98202.json"