Description
In the Linux kernel, the following vulnerability has been resolved:

platform/x86: lg-laptop: Fix LED resource handling

The event notification callback might access kbd_backlight even
when it was not successfully registered with the LED subsystem.
The same happens inside acpi_remove(), where the LED devices are
unregistered unconditionally.

Fix this by tracking the availability of the kbd_backlight LED
device and use devm_led_classdev_register() to let devres take
care of unregistering the LED devices during removal. For this
the parent device of the LED devices is changed to the native
platform device.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (kernel crash)
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel contains a bug in the LED subsystem for LG laptop platform devices where a callback may attempt to access the kbd_backlight LED device even when it has not been successfully registered. During hardware removal, the code also unconditionally unregisters LED devices that may not exist. If the driver accesses an unregistered device, it can dereference a null or stale pointer, causing a kernel crash and potentially a system reboot. This bug does not provide an information disclosure or code execution pathway, but it can terminate the kernel, leading to service interruption.

Affected Systems

The vulnerability affects all Linux kernel builds that include the LG laptop platform drivers before the commit that introduces the fix. Since the issue is tied to the generic kernel, it applies to all distributions running a vulnerable kernel version, regardless of vendor or OS edition. Users of stock kernel images or custom builds that have not applied the patch are impacted.

Risk and Exploitability

The CVSS score is not supplied, but the EPSS score is listed as < 1%, indicating a very low probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires an attacker to trigger a hardware event that causes the faulty callback, which is unlikely in ordinary operation. Consequently, the overall risk has been deemed low, though the impact would be severe if triggered.

Generated by OpenCVE AI on September 19, 2026 at 07:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the commit fixing the LED resource handling bug (e.g., a release after the changes in the referenced patches).
  • Ensure that any third‑party ACPI or LED drivers are also updated to the same or newer commit that adopts the corrected unregister logic.
  • If operating in an environment where unplanned hardware events can occur, consider disabling the kbd_backlight LED device via /sys to prevent the callback from accessing it during device removal.

Generated by OpenCVE AI on September 19, 2026 at 07:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: platform/x86: lg-laptop: Fix LED resource handling The event notification callback might access kbd_backlight even when it was not successfully registered with the LED subsystem. The same happens inside acpi_remove(), where the LED devices are unregistered unconditionally. Fix this by tracking the availability of the kbd_backlight LED device and use devm_led_classdev_register() to let devres take care of unregistering the LED devices during removal. For this the parent device of the LED devices is changed to the native platform device.
Title platform/x86: lg-laptop: Fix LED resource handling
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:31.933Z

Reserved: 2026-09-17T16:02:15.087Z

Link: CVE-2026-93128

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:07.570

Modified: 2026-09-17T17:18:07.570

Link: CVE-2026-93128

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T16:00:13Z

Weaknesses