« Volver al listado

CVE-2026-93128

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

platform/x86: lg-laptop: Fix LED resource handling

The event notification callback might access kbd_backlight even when it was not successfully registered with the LED subsystem. The same happens inside acpi_remove(), where the LED devices are unregistered unconditionally.

Fix this by tracking the availability of the kbd_backlight LED device and use devm_led_classdev_register() to let devres take care of unregistering the LED devices during removal. For this the parent device of the LED devices is changed to the native platform device.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93128",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ae26278829a80ad0e60ff004de71e9276cee5dc0",
              "lessThan": "4fbfe3714f645b6c64c9ba8faa83b27e4c9f2edd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ae26278829a80ad0e60ff004de71e9276cee5dc0",
              "lessThan": "9a85e2d35e54248aca39bad4f4152ed34de1995f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ae26278829a80ad0e60ff004de71e9276cee5dc0",
              "lessThan": "acc190322250562d5f28860f4ae1ebaf3e304fc2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ae26278829a80ad0e60ff004de71e9276cee5dc0",
              "lessThan": "3e91964aa74ab261aa15d9d96318eded2fd9d22a",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/platform/x86/lg-laptop.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/platform/x86/lg-laptop.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:18:07.570",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3e91964aa74ab261aa15d9d96318eded2fd9d22a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4fbfe3714f645b6c64c9ba8faa83b27e4c9f2edd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9a85e2d35e54248aca39bad4f4152ed34de1995f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/acc190322250562d5f28860f4ae1ebaf3e304fc2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: lg-laptop: Fix LED resource handling\n\nThe event notification callback might access kbd_backlight even\nwhen it was not successfully registered with the LED subsystem.\nThe same happens inside acpi_remove(), where the LED devices are\nunregistered unconditionally.\n\nFix this by tracking the availability of the kbd_backlight LED\ndevice and use devm_led_classdev_register() to let devres take\ncare of unregistering the LED devices during removal. For this\nthe parent device of the LED devices is changed to the native\nplatform device."
    }
  ],
  "lastModified": "2026-09-17T17:18:07.570",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}