« Volver al listado

CVE-2026-93251

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ACPI: bus: Introduce acpi_bus_get_primary_device()

The function used for obtaining the first "physical" device for which the given ACPI one is the ACPI companion, acpi_get_first_physical_node(), may return a stale device pointer (mostly in theory) because acpi_unbind_one() may run as a whole after dropping the ACPI device's physical_node_lock in acpi_get_first_physical_node() and before it returns. The last reference to the "physical" device may be dropped then before the pointer to it is returned to the caller.

If that happens and the acpi_get_first_physical_node() caller invokes get_device() on the pointer obtained from it, which is done by the majority of its callers, a use-after-free will occur.

Leer descripción completaMostrar menos

To prepare for addressing this problem, introduce a new function for getting the first "physical" device associated with the given ACPI one (the "primary physical device") that will also reference count the device in question before returning a pointer to it.

Make that new function and acpi_get_first_physical_node() share the physical node list lookup code.

No intentional functional impact.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93251",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "91e5687805885f9fceb60b95e950a3d3bdcf4764",
              "lessThan": "5657859851abb65105220a6cdb5804926249f714",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "91e5687805885f9fceb60b95e950a3d3bdcf4764",
              "lessThan": "72530e1f72b0515a73fd88292254d04fecf03649",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/acpi/bus.c",
            "include/acpi/acpi_bus.h"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.8"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.8",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/acpi/bus.c",
            "include/acpi/acpi_bus.h"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T16:17:21.340",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/5657859851abb65105220a6cdb5804926249f714",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/72530e1f72b0515a73fd88292254d04fecf03649",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: bus: Introduce acpi_bus_get_primary_device()\n\nThe function used for obtaining the first \"physical\" device for which\nthe given ACPI one is the ACPI companion, acpi_get_first_physical_node(),\nmay return a stale device pointer (mostly in theory) because\nacpi_unbind_one() may run as a whole after dropping the ACPI device's\nphysical_node_lock in acpi_get_first_physical_node() and before it\nreturns.  The last reference to the \"physical\" device may be dropped\nthen before the pointer to it is returned to the caller.\n\nIf that happens and the acpi_get_first_physical_node() caller invokes\nget_device() on the pointer obtained from it, which is done by the\nmajority of its callers, a use-after-free will occur.\n\nTo prepare for addressing this problem, introduce a new function for\ngetting the first \"physical\" device associated with the given ACPI one\n(the \"primary physical device\") that will also reference count the\ndevice in question before returning a pointer to it.\n\nMake that new function and acpi_get_first_physical_node() share the\nphysical node list lookup code.\n\nNo intentional functional impact."
    }
  ],
  "lastModified": "2026-09-25T13:17:18.220",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}