-

CVE-2026-93251

ACPI: bus: Introduce acpi_bus_get_primary_device()

In the Linux kernel, the following vulnerability has been resolved:

ACPI: bus: Introduce acpi_bus_get_primary_device()

The function used for obtaining the first "physical" device for which
the given ACPI one is the ACPI companion, acpi_get_first_physical_node(),
may return a stale device pointer (mostly in theory) because
acpi_unbind_one() may run as a whole after dropping the ACPI device's
physical_node_lock in acpi_get_first_physical_node() and before it
returns.  The last reference to the "physical" device may be dropped
then before the pointer to it is returned to the caller.

If that happens and the acpi_get_first_physical_node() caller invokes
get_device() on the pointer obtained from it, which is done by the
majority of its callers, a use-after-free will occur.

To prepare for addressing this problem, introduce a new function for
getting the first "physical" device associated with the given ACPI one
(the "primary physical device") that will also reference count the
device in question before returning a pointer to it.

Make that new function and acpi_get_first_physical_node() share the
physical node list lookup code.

No intentional functional impact.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 91e5687805885f9fceb60b95e950a3d3bdcf4764
Version < 5657859851abb65105220a6cdb5804926249f714
Status affected
Version 91e5687805885f9fceb60b95e950a3d3bdcf4764
Version < 72530e1f72b0515a73fd88292254d04fecf03649
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.8
Status affected
Version 0
Version < 3.8
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.076
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/5657859851abb65105220a6cdb5804926249f714
https://git.kernel.org/stable/c/72530e1f72b0515a73fd88292254d04fecf03649