Description
In the Linux kernel, the following vulnerability has been resolved:

platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL

Every platform driver can be forced to match a device that doesn't match
its list of device IDs because of device_match_driver_override(), so
platform drivers that rely on the existence of a device's ACPI companion
object need to verify its presence.

mlxbf_pmc_probe() passes the result of ACPI_COMPANION() to
acpi_device_hid(), which dereferences it, so force-binding the driver to
a device without an ACPI companion leads to a NULL pointer dereference.

Accordingly, add a requisite ACPI_COMPANION() check against NULL to the
mlxbf-pmc driver and return -ENODEV when the companion is missing.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

A null pointer dereference in the Mellanox platform driver for the PMC module causes a kernel oops when the driver is bound to a device that lacks an ACPI companion object. The code passes the companion pointer to a helper that dereferences it without checking for null. When an attacker forces the driver onto such a device, the kernel crashes, resulting in a system reboot or loss of service. The vulnerability does not provide direct remote code execution or privilege escalation, but it can interrupt critical workloads. The weakness is a classic null pointer dereference (CWE‑476).

Affected Systems

All Linux kernel builds that include the unpatched mlxbf‑pmc driver are affected. The driver is part of the official kernel source tree, so any distribution that ships a kernel containing this driver before the fix is potentially vulnerable. No specific kernel version range is listed, so every kernel revision that has the bug is at risk.

Risk and Exploitability

The EPSS score indicates a very low likelihood of exploitation in the wild (<1 %). The vulnerability is not listed in the CISA KEV catalog. Attackers would need to force the driver onto a device that does not provide an ACPI companion, which typically requires local privilege or the ability to invoke device_match_driver_override(). This vector is inferred from the description: the patch notes mention forced binding as the trigger. With local root privileges the exploit is trivial; without such access, exploitation is unlikely. Overall risk is moderate due to the low exploitation probability but high impact upon successful exploitation.

Generated by OpenCVE AI on September 19, 2026 at 09:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a revision that contains the fixed NULL check for ACPI_COMPANION() in mlxbf‑pmc probe.
  • If an updated kernel is unavailable, avoid using device_match_driver_override() to bind the mlxbf‑pmc driver to devices that lack an ACPI companion, thereby preventing the dereference.
  • Apply any vendor‑specific kernel patches or advisories that address this kernel bug and review the system log for kernel oops indications.

Generated by OpenCVE AI on September 19, 2026 at 09:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL Every platform driver can be forced to match a device that doesn't match its list of device IDs because of device_match_driver_override(), so platform drivers that rely on the existence of a device's ACPI companion object need to verify its presence. mlxbf_pmc_probe() passes the result of ACPI_COMPANION() to acpi_device_hid(), which dereferences it, so force-binding the driver to a device without an ACPI companion leads to a NULL pointer dereference. Accordingly, add a requisite ACPI_COMPANION() check against NULL to the mlxbf-pmc driver and return -ENODEV when the companion is missing.
Title platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:23.145Z

Reserved: 2026-09-17T16:02:15.086Z

Link: CVE-2026-93115

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:06.073

Modified: 2026-09-17T17:18:06.073

Link: CVE-2026-93115

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:30:06Z

Weaknesses