-

CVE-2026-100072

ACPI: platform: Use acpi_bus_get_primary_device()

In the Linux kernel, the following vulnerability has been resolved:

ACPI: platform: Use acpi_bus_get_primary_device()

The acpi_get_first_physical_node() usage in acpi_platform_fill_resource()
and acpi_create_platform_device() is generally unsafe because in theory
the device returned by it may be freed at any time [1].

It is also inefficient because acpi_get_first_physical_node() is called
multiple times for the same argument which can be avoided.

Address these issues by using acpi_bus_get_primary_device() instead of
acpi_get_first_physical_node() and adjusting the code to call it just
once at the beginning of and acpi_create_platform_device() and drop
the device reference acquired by it upon the return from that function.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 3b95bd160547f56a68aeb972c33ae9511e7a8380
Version < c9d202d3b6c28e8c779cd2f2b10d2f7ab665ca71
Status affected
Version 3b95bd160547f56a68aeb972c33ae9511e7a8380
Version < a9ba4dd2f18bf3f439d9ef0d8f375f90360ba1bd
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.6
Status affected
Version 0
Version < 4.6
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.031
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/c9d202d3b6c28e8c779cd2f2b10d2f7ab665ca71
https://git.kernel.org/stable/c/a9ba4dd2f18bf3f439d9ef0d8f375f90360ba1bd