CVE-2026-23443
In the Linux kernel, the following vulnerability has been resolved:
ACPI: processor: Fix previous acpi_processor_errata_piix4() fix
After commi f132e089fe89 ("ACPI: processor: Fix NULL-pointer dereference in acpi_processor_errata_piix4()"), device pointers may be dereferenced after dropping references to the device objects pointed to by them, which may cause a use-after-free to occur.
Moreover, debug messages about enabling the errata may be printed if the errata flags corresponding to them are unset.
Address all of these issues by moving message printing to the points in the code where the errata flags are set.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.12%
- Percentil entre todas las CVEs puntuadas: 2
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-476
Referencias
- https://git.kernel.org/stable/c/2e369ba9eb7b8a06e9cc35a3e7fe73e59272f8c2
- https://git.kernel.org/stable/c/68408e8f9e366ad9850a66ac65cb569f13bf6cd4
- https://git.kernel.org/stable/c/8583f62259e1b315d5239371adfb36939cdab741
- https://git.kernel.org/stable/c/98473309a36acc271009b85e0bb53a4c0dddf5c2
- https://git.kernel.org/stable/c/bf504b229cb8d534eccbaeaa23eba34c05131e25
- https://git.kernel.org/stable/c/e0c470049344e9346fff79d7e2362212c216665e
- https://git.kernel.org/stable/c/edf4c2aaee08e8fd503fbae705c801e92a0b55d7
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-23443",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "06724a60cfa9767ea90b0f5d3dfb5cdd251b64f5",
"lessThan": "68408e8f9e366ad9850a66ac65cb569f13bf6cd4",
"versionType": "git"
},
{
"status": "affected",
"version": "ad86ac604f8391c0212a91412d4f764c7a85f254",
"lessThan": "2e369ba9eb7b8a06e9cc35a3e7fe73e59272f8c2",
"versionType": "git"
},
{
"status": "affected",
"version": "01e8751b37a366b1ca561add0042f2ceb18c03bf",
"lessThan": "edf4c2aaee08e8fd503fbae705c801e92a0b55d7",
"versionType": "git"
},
{
"status": "affected",
"version": "b803811485ac0b2f774b6bf3abc8b999ba3b7033",
"lessThan": "e0c470049344e9346fff79d7e2362212c216665e",
"versionType": "git"
},
{
"status": "affected",
"version": "29f60d3d06818d40118a30d663231f027ae87a05",
"lessThan": "98473309a36acc271009b85e0bb53a4c0dddf5c2",
"versionType": "git"
},
{
"status": "affected",
"version": "0398b641be2b66c2fc7e0163c606ef19372e7ad5",
"lessThan": "8583f62259e1b315d5239371adfb36939cdab741",
"versionType": "git"
},
{
"status": "affected",
"version": "f132e089fe89cadc2098991f0a3cb05c3f824ac6",
"lessThan": "bf504b229cb8d534eccbaeaa23eba34c05131e25",
"versionType": "git"
}
],
"programFiles": [
"drivers/acpi/acpi_processor.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15.202",
"lessThan": "5.15.203",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.1.165",
"lessThan": "6.1.167",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.6.128",
"lessThan": "6.6.130",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.12.75",
"lessThan": "6.12.78",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.18.16",
"lessThan": "6.18.20",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.19.6",
"lessThan": "6.19.10",
"versionType": "semver"
}
],
"programFiles": [
"drivers/acpi/acpi_processor.c"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-04-03T16:16:28.573",
"references": [
{
"url": "https://git.kernel.org/stable/c/2e369ba9eb7b8a06e9cc35a3e7fe73e59272f8c2",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/68408e8f9e366ad9850a66ac65cb569f13bf6cd4",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8583f62259e1b315d5239371adfb36939cdab741",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/98473309a36acc271009b85e0bb53a4c0dddf5c2",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bf504b229cb8d534eccbaeaa23eba34c05131e25",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e0c470049344e9346fff79d7e2362212c216665e",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/edf4c2aaee08e8fd503fbae705c801e92a0b55d7",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-476"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: processor: Fix previous acpi_processor_errata_piix4() fix\n\nAfter commi f132e089fe89 (\"ACPI: processor: Fix NULL-pointer dereference\nin acpi_processor_errata_piix4()\"), device pointers may be dereferenced\nafter dropping references to the device objects pointed to by them,\nwhich may cause a use-after-free to occur.\n\nMoreover, debug messages about enabling the errata may be printed\nif the errata flags corresponding to them are unset.\n\nAddress all of these issues by moving message printing to the points\nin the code where the errata flags are set."
},
{
"lang": "es",
"value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nACPI: processor: Corrige la corrección anterior de acpi_processor_errata_piix4()\n\nDespués del commit f132e089fe89 ('ACPI: processor: Corrige la desreferenciación de puntero NULL en acpi_processor_errata_piix4()'), los punteros de dispositivo pueden ser desreferenciados después de eliminar las referencias a los objetos de dispositivo a los que apuntan, lo que puede causar un uso después de liberación.\n\nAdemás, los mensajes de depuración sobre la habilitación de las erratas pueden imprimirse si las banderas de errata correspondientes a ellas no están establecidas.\n\nAborda todos estos problemas moviendo la impresión de mensajes a los puntos en el código donde las banderas de errata están establecidas."
}
],
"lastModified": "2026-07-24T21:10:00.143",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D54E2FD5-7EF9-426A-9AE1-8E8DA970BCC8",
"versionEndExcluding": "6.1.167",
"versionStartIncluding": "6.1.165"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2099D3D0-97C6-44C5-913D-E616B07A9237",
"versionEndExcluding": "6.6.130",
"versionStartIncluding": "6.6.128"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DAB9F88E-FB55-4FDB-966E-E7FC262B2038",
"versionEndExcluding": "6.12.78",
"versionStartIncluding": "6.12.75"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "234D2F07-A17A-49BE-8B89-9C6756315A38",
"versionEndExcluding": "6.18.20",
"versionStartIncluding": "6.18.16"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "20A592B7-9A05-4B02-A583-F1B95CD93223",
"versionEndExcluding": "6.19.10",
"versionStartIncluding": "6.19.6"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.15.202:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "822A7BB5-FF38-425A-B8A8-9F102CF92C36"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}