Impact
The flaw occurs during platform driver probe when the kernel dereferences the ACPI companion object without first confirming it is non‑NULL. If a driver is forced to bind to a device that does not expose an ACPI companion, the code will dereference a NULL pointer, causing a kernel panic. This crash can terminate the operating system or a running process, effectively denying service for local users that have the ability to trigger the binding.
Affected Systems
The issue exists in all Linux kernel releases that include the platform/surface driver code before the null‑check was added in the referenced commit. It affects any system that loads this driver and may allow a device to be bound to it through device_match_driver_override or similar mechanisms. The vulnerability is vendor specific to the Linux kernel, and no specific version ranges are listed in the advisory.
Risk and Exploitability
The EPSS score for this vulnerability is reported as less than 1 %, indicating a low probability of exploitation in the wild. The vulnerability is not included in CISA’s Known Exploited Vulnerabilities catalog. There is no publicly available CVSS score in the advisory, but the nature of the flaw—pointer dereference during driver initialization—implies a high potential impact if an attacker can force the driver into a bad state. The likely attack vector is local, requiring the ability to influence driver binding or the device tree to trigger the kernel crash.
OpenCVE Enrichment
Debian DLA
Debian DSA