Description
In the Linux kernel, the following vulnerability has been resolved:

drm/i915: Guard against NULL driver_data in i915_pci_probe()

pci_match_device() can return the dummy pci_device_id_any entry
when a device is force-bound via sysfs driver_override, in which
case ->driver_data is unset (NULL). i915_pci_probe() casts it to
struct intel_device_info * unconditionally and dereferences
intel_info->require_force_probe, causing a NULL-ptr-deref.

(cherry picked from commit 2727922084672cc274ecea726ea00363c2893731)
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability stems from the i915 driver’s probe routine incorrectly assuming that driver_data is always present. When a device is forced‑bound via sysfs driver_override, pci_match_device() can return a dummy entry whose driver_data field is NULL. The probe code casts this NULL pointer to a struct intel_device_info and then dereferences it, leading to a null pointer dereference that causes a kernel crash. This results in a loss of availability as the kernel panics and the system becomes unresponsive.

Affected Systems

All Linux kernels that ship the i915 graphics driver before the commit 2727922084672cc274ecea726ea00363c2893731. The affected product is the Linux kernel; any distribution running an unpatched kernel version is susceptible.

Risk and Exploitability

The flaw only triggers a local denial of service; it does not allow privilege escalation or arbitrary code execution. The exploitation probability is very low (EPSS < 1%) and the vulnerability is not yet listed in the CISA Known Exploited Vulnerabilities catalog. An attacker would need local access to modify the sysfs driver_override attribute for an i915 device to force the driver to load and expose the bug. Given the low probability and local nature, the overall risk remains modest, but a patch should be applied to eliminate the crash risk.

Generated by OpenCVE AI on September 18, 2026 at 09:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the fix introduced by commit 2727922084672cc274ecea726ea00363c2893731.
  • If an immediate kernel upgrade is not possible, remove or revert any sysfs driver_override changes that force-bind the i915 driver so the probe path does not encounter a NULL driver_data.
  • Monitor kernel logs for Oops or panic messages related to the i915 driver; if such events occur, re‑evaluate the kernel version and apply the patch as soon as feasible.

Generated by OpenCVE AI on September 18, 2026 at 09:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/i915: Guard against NULL driver_data in i915_pci_probe() pci_match_device() can return the dummy pci_device_id_any entry when a device is force-bound via sysfs driver_override, in which case ->driver_data is unset (NULL). i915_pci_probe() casts it to struct intel_device_info * unconditionally and dereferences intel_info->require_force_probe, causing a NULL-ptr-deref. (cherry picked from commit 2727922084672cc274ecea726ea00363c2893731)
Title drm/i915: Guard against NULL driver_data in i915_pci_probe()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T09:29:15.310Z

Reserved: 2026-09-11T19:38:34.768Z

Link: CVE-2026-89822

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:47.640

Modified: 2026-09-17T10:17:04.700

Link: CVE-2026-89822

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:15:16Z

Weaknesses