Description
In the Linux kernel, the following vulnerability has been resolved:

platform/x86: asus-wireless: Fail probe when there is no ACPI match

Every platform driver can be forced to match a device that does not match
its list of device IDs because of device_match_driver_override(), so
platform drivers that rely on the existence of a device ACPI companion
object need to verify its presence.

asus_wireless_probe() returns success when acpi_match_acpi_device()
finds no match, leaving behind an input device that never reports
anything because the notify handler is not installed. Worse, when the
driver is force-bound to a device without an ACPI companion, probe
still succeeds and stores a NULL companion pointer, which
asus_wireless_remove() later passes to acpi_dev_remove_notify_handler(),
leading to a NULL pointer dereference on unbind.

Return -ENODEV when the device does not match the ID table. This also
covers the missing-companion case, because acpi_match_acpi_device()
rejects a NULL device. Perform the check before allocating any driver
state, instead of after the input device has already been registered.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises because the asus_wireless platform driver accepts a probe request even when no matching ACPI device is found. This leaves the driver in a partially initialized state with a NULL companion pointer. When the driver later attempts to remove the device, it dereferences this NULL pointer, causing a kernel crash. The crash could be triggered locally by an attacker who can force the driver to bind to a device without a proper ACPI companion, providing a vector for denial of service. The weakness is a classic null pointer dereference, making control of driver loading a critical concern.

Affected Systems

The defect is present in the Linux kernel’s ASUS wireless platform driver on x86 architectures. No specific kernel version range is listed, but any kernel that includes the unpatched asus_wireless driver is affected. The vulnerability applies to any system running a platform driver that uses the force-bind mechanism without verifying the presence of a matching ACPI companion.

Risk and Exploitability

The CVSS metric is not provided, but a NULL pointer dereference that can crash the kernel is considered high severity. The EPSS score is below 1 %, indicating a very low predicted exploitation probability at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local driver load or a forced binding operation performed by a user with sufficient privileges to load kernel modules. An attacker could trigger the fault by binding the asus_wireless driver to a device without an ACPI companion, leading to a kernel panic and system disruption.

Generated by OpenCVE AI on September 19, 2026 at 08:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that contains the patch correcting the probe logic for the asus_wireless driver
  • Modify or restrict driver binding so that the asus_wireless driver is only bound to devices that have a valid ACPI companion object
  • If an update cannot be applied immediately, disable or unload the asus_wireless driver on affected systems to prevent the NULL dereference during module removal

Generated by OpenCVE AI on September 19, 2026 at 08:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: platform/x86: asus-wireless: Fail probe when there is no ACPI match Every platform driver can be forced to match a device that does not match its list of device IDs because of device_match_driver_override(), so platform drivers that rely on the existence of a device ACPI companion object need to verify its presence. asus_wireless_probe() returns success when acpi_match_acpi_device() finds no match, leaving behind an input device that never reports anything because the notify handler is not installed. Worse, when the driver is force-bound to a device without an ACPI companion, probe still succeeds and stores a NULL companion pointer, which asus_wireless_remove() later passes to acpi_dev_remove_notify_handler(), leading to a NULL pointer dereference on unbind. Return -ENODEV when the device does not match the ID table. This also covers the missing-companion case, because acpi_match_acpi_device() rejects a NULL device. Perform the check before allocating any driver state, instead of after the input device has already been registered.
Title platform/x86: asus-wireless: Fail probe when there is no ACPI match
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:29.223Z

Reserved: 2026-09-17T16:02:15.087Z

Link: CVE-2026-93124

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:07.137

Modified: 2026-09-17T17:18:07.137

Link: CVE-2026-93124

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T16:00:13Z

Weaknesses