Description
In the Linux kernel, the following vulnerability has been resolved:

ACPI: RISC-V: Check acpi_get_handle() status in riscv_acpi_add_prt_dep()

In riscv_acpi_add_prt_dep(), the acpi_get_handle() call can fail which
would leave link_handle uninitialized.

Fix it by checking the acpi_get_handle() return status and skip the entry
if it fails.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel contains a flaw in the RISC‑V ACPI driver where a call to acpi_get_handle() can fail, but its return value is not checked. This oversight leaves the variable link_handle uninitialized, and subsequent use of that uninitialized pointer can cause the kernel to crash or behave unpredictably. The weakness is a classic instance of an uninitialized variable (CWE‑758). The resulting system instability manifests as a denial‑of‑service condition since the kernel may panic and halt the system.

Affected Systems

The affected product is the Linux operating system. All builds of the Linux kernel that include the RISC‑V ACPI subsystem prior to the commit that added a status check on acpi_get_handle() are vulnerable. No specific version numbers are supplied in the advisory, so any kernel not yet updated with the fix is considered impacted.

Risk and Exploitability

The CVSS metric is not provided, but the EPSS score indicates an extremely low probability of exploitation—less than 1%. The vulnerability is not listed in CISA’s KEV catalog, and no public exploits are known. Because the flaw requires interaction with ACPI device code, the most likely attack vector is a local privileged user who can trigger ACPI evaluation. While the potential impact is severe (kernel crash), the combination of low EPSS and lack of published exploits suggests a moderate overall risk if the system remains on an unpatched kernel.

Generated by OpenCVE AI on September 19, 2026 at 06:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the fix that checks acpi_get_handle() return status before using link_handle
  • If the kernel cannot be updated immediately, disable or limit ACPI device access that might trigger the vulnerable path, or disable ACPI functionality entirely for systems without a practical need for it
  • Monitor system logs for ACPI-related errors and kernel panics, and investigate any anomalous kernel crashes that may relate to the uninitialized link_handle bug

Generated by OpenCVE AI on September 19, 2026 at 06:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-758

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ACPI: RISC-V: Check acpi_get_handle() status in riscv_acpi_add_prt_dep() In riscv_acpi_add_prt_dep(), the acpi_get_handle() call can fail which would leave link_handle uninitialized. Fix it by checking the acpi_get_handle() return status and skip the entry if it fails.
Title ACPI: RISC-V: Check acpi_get_handle() status in riscv_acpi_add_prt_dep()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:35.383Z

Reserved: 2026-09-17T16:02:15.087Z

Link: CVE-2026-93133

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:08.157

Modified: 2026-09-17T17:18:08.157

Link: CVE-2026-93133

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:30:57Z

Weaknesses
  • CWE-758

    Reliance on Undefined, Unspecified, or Implementation-Defined Behavior