-

CVE-2026-93124

platform/x86: asus-wireless: Fail probe when there is no ACPI match

In the Linux kernel, the following vulnerability has been resolved:

platform/x86: asus-wireless: Fail probe when there is no ACPI match

Every platform driver can be forced to match a device that does not match
its list of device IDs because of device_match_driver_override(), so
platform drivers that rely on the existence of a device ACPI companion
object need to verify its presence.

asus_wireless_probe() returns success when acpi_match_acpi_device()
finds no match, leaving behind an input device that never reports
anything because the notify handler is not installed.  Worse, when the
driver is force-bound to a device without an ACPI companion, probe
still succeeds and stores a NULL companion pointer, which
asus_wireless_remove() later passes to acpi_dev_remove_notify_handler(),
leading to a NULL pointer dereference on unbind.

Return -ENODEV when the device does not match the ID table.  This also
covers the missing-companion case, because acpi_match_acpi_device()
rejects a NULL device.  Perform the check before allocating any driver
state, instead of after the input device has already been registered.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version f7e648027d7e1b5c06eb86d944b7e23926254cee
Version < 7bfa711f311a584002e16ecd750627306deb805c
Status affected
Version f7e648027d7e1b5c06eb86d944b7e23926254cee
Version < 4aefd66ef7822cf7d3f53146dcee0b71021ed2b7
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 7.1
Status affected
Version 0
Version < 7.1
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.051
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/7bfa711f311a584002e16ecd750627306deb805c
https://git.kernel.org/stable/c/4aefd66ef7822cf7d3f53146dcee0b71021ed2b7