Description
In the Linux kernel, the following vulnerability has been resolved:

ACPI: scan: fix bus ID cleanup on device_add() failures

When device_add() fails after acpi_device_set_name() has allocated an
instance ID and a new acpi_device_bus_id has been linked into
acpi_bus_id_list, the rollback path only removes wakeup_list and
detaches the ACPI handle data.

That leaves the bus-ID bookkeeping behind and keeps the allocated
instance number consumed.

Move the bus-ID cleanup and wakeup-list removal into a single helper.

Use it from both the normal device teardown path and the device_add()
rollback path. The wakeup list node is initialized before registration,
so it can be deleted without checking whether the device is wakeup-
capable like in the original teardown path.

[ rjw: Rename acpi_device_del_list() to acpi_device_cleanup() ]
[ rjw: Subject and changelog edits ]
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service – resource exhaustion due to unreleased ACPI bus IDs
Action: Patch
AI Analysis

Impact

A flaw in the Linux kernel ACPI subsystem causes an incomplete rollback when an ACPI device fails to be added after its instance ID and bus ID have been allocated. The rollback path removes only the wakeup list while leaving the bus‑ID bookkeeping in place, which permanently consumes the instance number. Over time, this leaks identifier resources, potentially exhausting the pool of available bus IDs and preventing new ACPI devices from being enumerated.

Affected Systems

All Linux kernel releases that predate the ACPI bus‑ID cleanup fix, i.e., the mainline Linux kernel versions that do not include the commit that introduces the helper for bus‑ID and wakeup‑list cleanup.

Risk and Exploitability

The vulnerability does not provide for code execution or privilege escalation. Exploitation requires the attacker to cause a device_add failure, typically under privileged or boot conditions. The EPSS score is reported as less than 1 %, and the flaw is not listed in the CISA KEV catalog, indicating a low probability of real‑world exploitation. Nonetheless, repeated failures could lead to service disruption by exhausting ACPI bus ID resources.

Generated by OpenCVE AI on September 20, 2026 at 01:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that merges bus‑ID cleanup into the shared helper, or upgrade to a kernel release that contains the change
  • If an immediate kernel upgrade is not possible, consider temporarily disabling hot‑plug ACPI enumeration or limiting the number of ACPI devices exposed to the kernel to mitigate ID exhaustion
  • Temporarily disable ACPI enumeration by setting kernel parameter acpi=off until a patched kernel is available

Generated by OpenCVE AI on September 20, 2026 at 01:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-666
CWE-668

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ACPI: scan: fix bus ID cleanup on device_add() failures When device_add() fails after acpi_device_set_name() has allocated an instance ID and a new acpi_device_bus_id has been linked into acpi_bus_id_list, the rollback path only removes wakeup_list and detaches the ACPI handle data. That leaves the bus-ID bookkeeping behind and keeps the allocated instance number consumed. Move the bus-ID cleanup and wakeup-list removal into a single helper. Use it from both the normal device teardown path and the device_add() rollback path. The wakeup list node is initialized before registration, so it can be deleted without checking whether the device is wakeup- capable like in the original teardown path. [ rjw: Rename acpi_device_del_list() to acpi_device_cleanup() ] [ rjw: Subject and changelog edits ]
Title ACPI: scan: fix bus ID cleanup on device_add() failures
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:14.317Z

Reserved: 2026-09-11T19:38:34.792Z

Link: CVE-2026-90194

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:14.150

Modified: 2026-09-17T17:17:14.150

Link: CVE-2026-90194

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:45:17Z

Weaknesses
  • CWE-666

    Operation on Resource in Wrong Phase of Lifetime

  • CWE-668

    Exposure of Resource to Wrong Sphere