Description
In the Linux kernel, the following vulnerability has been resolved:

iio: pressure: dps310: fix NULL pointer dereference on ACPI probe

When the device is enumerated through its ACPI HID (IFX3100),
i2c_client_get_device_id() returns NULL: the ACPI-derived client name
does not match the driver's i2c_device_id table. dps310_probe() then
dereferences that NULL pointer in "iio->name = id->name" and crashes the
kernel during probe.

The IIO device name is always "dps310", so set it directly and drop the
now-unused device-id lookup.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

In the Linux kernel IIO pressure driver for the dps310 sensor, enumeration via the ACPI HID IFX3100 leads to a NULL pointer dereference during probe, causing a kernel crash and resulting in a denial of service because the operating system becomes unstable or hangs. The weakness arises from dereferencing a device identifier that does not exist in the driver’s device ID table. The crash manifests as a fatal kernel oops that typically forces a reboot, disrupting services on the affected host.

Affected Systems

The vulnerability affects Linux kernels that include the dps310 IIO driver when ACPI enumeration is enabled for devices with the IFX3100 HID. Vendor products involve Linux kernel releases compiled with the dps310 driver; no specific version numbers are provided, so any kernel package containing the driver and ACPI support can be impacted.

Risk and Exploitability

The EPSS score is < 1% and the vulnerability is not listed in CISA KEV, indicating currently low exploitation probability. Despite the absence of an explicit CVSS value, a kernel crash carries a high impact rating. The attack vector is inferred to require either local or privileged access to trigger the ACPI probe for the IFX3100 sensor; remote exploitation is unlikely unless an attacker can influence device enumeration or firmware configuration.

Generated by OpenCVE AI on September 18, 2026 at 00:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that incorporates the dps310_probe null‑pointer fix, which assigns the device name directly and removes the vulnerable lookup.
  • If an immediate kernel update is not feasible, disable ACPI enumeration for IFX3100 devices via appropriate boot‑time parameters or firmware settings to prevent the probe from executing the vulnerable code path.
  • As a temporary workaround, modify the driver to set the IIO device name directly in the probe function, mirroring the upstream patch logic.

Generated by OpenCVE AI on September 18, 2026 at 00:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iio: pressure: dps310: fix NULL pointer dereference on ACPI probe When the device is enumerated through its ACPI HID (IFX3100), i2c_client_get_device_id() returns NULL: the ACPI-derived client name does not match the driver's i2c_device_id table. dps310_probe() then dereferences that NULL pointer in "iio->name = id->name" and crashes the kernel during probe. The IIO device name is always "dps310", so set it directly and drop the now-unused device-id lookup.
Title iio: pressure: dps310: fix NULL pointer dereference on ACPI probe
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:23.550Z

Reserved: 2026-09-11T19:38:34.776Z

Link: CVE-2026-89933

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:02.680

Modified: 2026-09-16T11:17:02.680

Link: CVE-2026-89933

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:30:16Z

Weaknesses