« Volver al listado

CVE-2026-92521

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root

acpi_pci_root_add() assigns the freshly allocated root to device->driver_data before dmar_device_add() and pci_acpi_scan_root(). Both failure paths reach the end: label where root is kfree()'d, but only the pci_acpi_scan_root() path clears driver_data first.

When dmar_device_add() fails during a hot-add, root is freed while device->driver_data still points at it. The ACPI core does not clear driver_data on attach failure, so a later acpi_pci_find_root() call may dereference this dangling pointer.

Leer descripción completaMostrar menos

acpi_pci_root_remove() has the same problem: it frees root without clearing device->driver_data, leaving a dangling pointer behind after the root bridge is removed.

Move the NULL assignment to the shared end: label so every error path in acpi_pci_root_add() clears driver_data before freeing root, and clear it in acpi_pci_root_remove() as well, so the object is never left reachable through driver_data after being freed.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-92521",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "db89b4f0dbab837d0f3de2c3e9427a8d5393afa3",
              "lessThan": "321bb0eb1486a0d575f02e24e3f4170e408c2f51",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "db89b4f0dbab837d0f3de2c3e9427a8d5393afa3",
              "lessThan": "3c1e8a14f9d06c1ed6f3e4bd2d283a62079109e2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "db89b4f0dbab837d0f3de2c3e9427a8d5393afa3",
              "lessThan": "a285fa3780c768dcc51c76768707d099a2cc611d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "db89b4f0dbab837d0f3de2c3e9427a8d5393afa3",
              "lessThan": "6aaf6dbf54fdfae096f3f90a79e9614e46579280",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "db89b4f0dbab837d0f3de2c3e9427a8d5393afa3",
              "lessThan": "70cf773cca30a10b4964c24520a71279c974b899",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "db89b4f0dbab837d0f3de2c3e9427a8d5393afa3",
              "lessThan": "3eee4c21931dc048ce63b86809f04e4e6f0dcad5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "db89b4f0dbab837d0f3de2c3e9427a8d5393afa3",
              "lessThan": "6e11ac626f9f9fc3a2ed27dfa44ccbe5fb762217",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "db89b4f0dbab837d0f3de2c3e9427a8d5393afa3",
              "lessThan": "8a742141f7ab84975aa758b775567ef4740ef0cf",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/acpi/pci_root.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.28"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.28",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/acpi/pci_root.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:55.013",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/321bb0eb1486a0d575f02e24e3f4170e408c2f51",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3c1e8a14f9d06c1ed6f3e4bd2d283a62079109e2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3eee4c21931dc048ce63b86809f04e4e6f0dcad5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6aaf6dbf54fdfae096f3f90a79e9614e46579280",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6e11ac626f9f9fc3a2ed27dfa44ccbe5fb762217",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/70cf773cca30a10b4964c24520a71279c974b899",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8a742141f7ab84975aa758b775567ef4740ef0cf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a285fa3780c768dcc51c76768707d099a2cc611d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root\n\nacpi_pci_root_add() assigns the freshly allocated root to\ndevice->driver_data before dmar_device_add() and pci_acpi_scan_root().\nBoth failure paths reach the end: label where root is kfree()'d, but\nonly the pci_acpi_scan_root() path clears driver_data first.\n\nWhen dmar_device_add() fails during a hot-add, root is freed while\ndevice->driver_data still points at it.  The ACPI core does not clear\ndriver_data on attach failure, so a later acpi_pci_find_root() call may\ndereference this dangling pointer.\n\nacpi_pci_root_remove() has the same problem: it frees root without\nclearing device->driver_data, leaving a dangling pointer behind after\nthe root bridge is removed.\n\nMove the NULL assignment to the shared end: label so every error path in\nacpi_pci_root_add() clears driver_data before freeing root, and clear it\nin acpi_pci_root_remove() as well, so the object is never left reachable\nthrough driver_data after being freed."
    }
  ],
  "lastModified": "2026-09-17T17:17:55.013",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}