Description
In the Linux kernel, the following vulnerability has been resolved:

ACPI: RISC-V: Fix riscv_acpi_add_prt_dep() loop handling

The loop in riscv_acpi_add_prt_dep() includes error conditions that are
handled in a dubious - if not outright wrong - way, by continuining the
loop (which skips and misses the entry pointer update to point to the next
entry).

Rewrite the loop as a for loop (that handles the continuation correctly)
and wrap the condition and update statements using helper functions to make
it cleaner.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Assess Impact
AI Analysis

Impact

The Linux kernel for RISC‑V contains a loop in riscv_acpi_add_prt_dep() that mishandles error conditions by continuing the loop without advancing the entry pointer. This logic flaw likely leads to incorrect ACPI table parsing and could cause kernel stalls or misconfigured devices. The description does not state that the flaw allows arbitrary memory read or write; it appears to affect only parsing logic, so the primary consequence is service disruption rather than privilege escalation.

Affected Systems

Linux kernel builds compiled for the RISC‑V architecture that include the original loop implementation are affected. The fix appears in the referenced commits, so any kernel version prior to those patches is vulnerable. Specific kernel release numbers are not provided, but the issue exists in all builds that have not yet incorporated the corrections.

Risk and Exploitability

The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation in the wild. Based on the description, an attacker would need to supply or influence ACPI tables processed during boot or device enumeration, a scenario that generally requires privileged or local access. If such a table is crafted, denial of service or incorrect configuration is possible, but overall risk is modest because the flaw does not provide direct arbitrary memory access or privilege elevation.

Generated by OpenCVE AI on September 19, 2026 at 07:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that contains the patch referenced in the audit commits.
  • If operating in an environment where ACPI tables can be trusted, disable ACPI on the target system until the kernel is updated.
  • Monitor kernel logs for ACPI parsing errors or crashes and investigate any anomalous device enumeration patterns.

Generated by OpenCVE AI on September 19, 2026 at 07:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-398

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ACPI: RISC-V: Fix riscv_acpi_add_prt_dep() loop handling The loop in riscv_acpi_add_prt_dep() includes error conditions that are handled in a dubious - if not outright wrong - way, by continuining the loop (which skips and misses the entry pointer update to point to the next entry). Rewrite the loop as a for loop (that handles the continuation correctly) and wrap the condition and update statements using helper functions to make it cleaner.
Title ACPI: RISC-V: Fix riscv_acpi_add_prt_dep() loop handling
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:34.708Z

Reserved: 2026-09-17T16:02:15.087Z

Link: CVE-2026-93132

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:08.047

Modified: 2026-09-17T17:18:08.047

Link: CVE-2026-93132

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:15:17Z

Weaknesses