Description
In the Linux kernel, the following vulnerability has been resolved:

platform/surface: acpi-notify: Check ACPI companion before use

Since every platform driver can be forced to match a device that doesn't
match its list of device IDs because of device_match_driver_override(),
platform drivers that rely on the existence of a device's ACPI companion
object should verify its presence.

san_probe() dereferences the result of ACPI_COMPANION() when installing
the GSBUS address space handler, so force-binding the driver to a device
without an ACPI companion leads to a NULL pointer dereference. The
dereference was introduced when the probe function was switched from
ACPI_HANDLE() to ACPI_COMPANION().

Check the ACPI companion against NULL and return -ENODEV when it is
missing, like commit e4865a56d013 ("ACPI: driver: Check ACPI_COMPANION()
against NULL during probe") does for the core ACPI platform drivers.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: local kernel crash leading to denial of service
Action: Apply patch
AI Analysis

Impact

The flaw occurs during platform driver probe when the kernel dereferences the ACPI companion object without first confirming it is non‑NULL. If a driver is forced to bind to a device that does not expose an ACPI companion, the code will dereference a NULL pointer, causing a kernel panic. This crash can terminate the operating system or a running process, effectively denying service for local users that have the ability to trigger the binding.

Affected Systems

The issue exists in all Linux kernel releases that include the platform/surface driver code before the null‑check was added in the referenced commit. It affects any system that loads this driver and may allow a device to be bound to it through device_match_driver_override or similar mechanisms. The vulnerability is vendor specific to the Linux kernel, and no specific version ranges are listed in the advisory.

Risk and Exploitability

The EPSS score for this vulnerability is reported as less than 1 %, indicating a low probability of exploitation in the wild. The vulnerability is not included in CISA’s Known Exploited Vulnerabilities catalog. There is no publicly available CVSS score in the advisory, but the nature of the flaw—pointer dereference during driver initialization—implies a high potential impact if an attacker can force the driver into a bad state. The likely attack vector is local, requiring the ability to influence driver binding or the device tree to trigger the kernel crash.

Generated by OpenCVE AI on September 19, 2026 at 07:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that incorporates the NULL check for ACPI_COMPANION() in the platform/surface driver.
  • If a full kernel upgrade is not yet available, backport the patch that adds the null guard to the offending driver source.
  • Verify that no force-binding utilities or device overrides can match the platform driver to devices lacking ACPI companions, and restrict such usage to trusted contexts.

Generated by OpenCVE AI on September 19, 2026 at 07:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: platform/surface: acpi-notify: Check ACPI companion before use Since every platform driver can be forced to match a device that doesn't match its list of device IDs because of device_match_driver_override(), platform drivers that rely on the existence of a device's ACPI companion object should verify its presence. san_probe() dereferences the result of ACPI_COMPANION() when installing the GSBUS address space handler, so force-binding the driver to a device without an ACPI companion leads to a NULL pointer dereference. The dereference was introduced when the probe function was switched from ACPI_HANDLE() to ACPI_COMPANION(). Check the ACPI companion against NULL and return -ENODEV when it is missing, like commit e4865a56d013 ("ACPI: driver: Check ACPI_COMPANION() against NULL during probe") does for the core ACPI platform drivers.
Title platform/surface: acpi-notify: Check ACPI companion before use
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:22.463Z

Reserved: 2026-09-17T16:02:15.086Z

Link: CVE-2026-93114

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:05.943

Modified: 2026-09-17T17:18:05.943

Link: CVE-2026-93114

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T23:00:09Z

Weaknesses