Description
In the Linux kernel, the following vulnerability has been resolved:

ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root

acpi_pci_root_add() assigns the freshly allocated root to
device->driver_data before dmar_device_add() and pci_acpi_scan_root().
Both failure paths reach the end: label where root is kfree()'d, but
only the pci_acpi_scan_root() path clears driver_data first.

When dmar_device_add() fails during a hot-add, root is freed while
device->driver_data still points at it. The ACPI core does not clear
driver_data on attach failure, so a later acpi_pci_find_root() call may
dereference this dangling pointer.

acpi_pci_root_remove() has the same problem: it frees root without
clearing device->driver_data, leaving a dangling pointer behind after
the root bridge is removed.

Move the NULL assignment to the shared end: label so every error path in
acpi_pci_root_add() clears driver_data before freeing root, and clear it
in acpi_pci_root_remove() as well, so the object is never left reachable
through driver_data after being freed.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free in ACPI PCI root handling can cause kernel crashes or privilege escalation
Action: Apply Patch
AI Analysis

Impact

The kernel driver for ACPI PCI roots does not clear its driver_data pointer when a root is freed, leaving a dangling reference. If an add or removal operation fails, the pointer remains set and later calls to acpi_pci_find_root may dereference it. This use‑after‑free can corrupt kernel memory or lead to arbitrary code execution with kernel privileges, effectively creating a serious kernel exploitation vector.

Affected Systems

All Linux kernel builds that have not incorporated the commits referenced in the matrix. The CPE indicates applicability to every version of the Linux kernel, and no specific version range is provided, so any system with the vulnerable kernel is potentially impacted.

Risk and Exploitability

The EPSS score is below 1% and the CVE is not listed in the CISA KEV catalogue, suggesting low observed exploitation activity. Nevertheless, the exploitation of a kernel use‑after‑free remains a high‑severity risk: a local or firmware‑based attacker could trigger ACPI hot‑add or removal paths to create the dangling pointer and then use defined memory corruption techniques to gain kernel privileges. The vulnerability is classified under CWE‑416.

Generated by OpenCVE AI on September 19, 2026 at 13:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that includes the patch referenced in the commit logs.
  • If a kernel upgrade is not immediately possible, disable ACPI PCI hot‑add functionality or block ACPI events that trigger root add or removal.
  • Watch for kernel oops, BUG, or panic messages that reference ACPI PCI root operations, and investigate any unexpected activity.

Generated by OpenCVE AI on September 19, 2026 at 13:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root acpi_pci_root_add() assigns the freshly allocated root to device->driver_data before dmar_device_add() and pci_acpi_scan_root(). Both failure paths reach the end: label where root is kfree()'d, but only the pci_acpi_scan_root() path clears driver_data first. When dmar_device_add() fails during a hot-add, root is freed while device->driver_data still points at it. The ACPI core does not clear driver_data on attach failure, so a later acpi_pci_find_root() call may dereference this dangling pointer. acpi_pci_root_remove() has the same problem: it frees root without clearing device->driver_data, leaving a dangling pointer behind after the root bridge is removed. Move the NULL assignment to the shared end: label so every error path in acpi_pci_root_add() clears driver_data before freeing root, and clear it in acpi_pci_root_remove() as well, so the object is never left reachable through driver_data after being freed.
Title ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:28.144Z

Reserved: 2026-09-16T12:21:13.874Z

Link: CVE-2026-92521

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:55.013

Modified: 2026-09-17T17:17:55.013

Link: CVE-2026-92521

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:15:16Z

Weaknesses