Description
In the Linux kernel, the following vulnerability has been resolved:

tpm_crb: Check ACPI_COMPANION() against NULL during probe

Every platform driver can be forced to match a device that doesn't match
its list of device IDs because of device_match_driver_override(), so
platform drivers that rely on the existence of a device's ACPI companion
object need to verify its presence.

Accordingly, add a requisite ACPI_COMPANION() check against NULL to the
tpm_crb driver.
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The tpm_crb driver had no test for the ACPI companion object during probe; if the driver is bound to a device that has no ACPI companion because device_match_driver_override forced the match, the driver dereferences a NULL pointer, causing a kernel panic that forces the operating system to reboot. This flaw is a classic null-pointer dereference and directly erodes system availability.

Affected Systems

All Linux kernel builds that contain the tpm_crb driver and have not applied the patch referenced by the kernel commit, including standard distribution kernels and custom source builds that include this driver. Users of any Linux distribution that has not yet rolled the latest stable kernel (or patched the kernel manually) are affected.

Risk and Exploitability

Certified exploit metrics are currently unavailable; EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog. The flaw can be triggered by using the device_match_driver_override API to force the tpm_crb driver onto a device that has no ACPI companion. Based on the description, it is inferred that the API is intended for privileged users; a user with root-level access could thus cause the driver to dereference a NULL pointer, resulting in a kernel panic and system reboot. While no public exploit is known, the possibility of a local privileged attacker inducing an OS crash represents a high risk for environments where root access is possible. The CVSS score of 5.5 indicates a moderate severity.

Generated by OpenCVE AI on August 22, 2026 at 03:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the kernel to a version that includes the patch adding the null-check for the ACPI companion object in tpm_crb.
  • If an immediate upgrade cannot be performed, restrict or disable the device_match_driver_override interface so only trusted users can invoke it.
  • Monitor system logs for kernel panic events and apply the kernel patch as soon as it is available.

Generated by OpenCVE AI on August 22, 2026 at 03:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Sat, 15 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: tpm_crb: Check ACPI_COMPANION() against NULL during probe Every platform driver can be forced to match a device that doesn't match its list of device IDs because of device_match_driver_override(), so platform drivers that rely on the existence of a device's ACPI companion object need to verify its presence. Accordingly, add a requisite ACPI_COMPANION() check against NULL to the tpm_crb driver.
Title tpm_crb: Check ACPI_COMPANION() against NULL during probe
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:14:32.158Z

Reserved: 2026-08-09T03:40:39.929Z

Link: CVE-2026-72432

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:17.057

Modified: 2026-08-17T06:19:10.530

Link: CVE-2026-72432

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72432 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T03:30:16Z

Weaknesses