{"id":"CVE-2026-93114","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/surface: acpi-notify: Check ACPI companion before use\n\nSince every platform driver can be forced to match a device that doesn't\nmatch its list of device IDs be…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/surface: acpi-notify: Check ACPI companion before use\n\nSince every platform driver can be forced to match a device that doesn't\nmatch its list of device IDs be…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= a9e10e58730432e5de840eb3ddd55c75f29341b3 < 4faa43d4ef0b98beb6c2b77a279f4aa5d7fa2d13","Linux >= a9e10e58730432e5de840eb3ddd55c75f29341b3 < 3855be0100efb98c26228c610db70a673611f3bd","Linux >= a9e10e58730432e5de840eb3ddd55c75f29341b3 < f276b62f2ce1cbff7fa50a8ee5afd8fef5a60897","Linux >= a9e10e58730432e5de840eb3ddd55c75f29341b3 < 9b6479da662c2ec4e931ed9f7228df46aa8c3766","Linux >= a9e10e58730432e5de840eb3ddd55c75f29341b3 < 7fea5a310e3b2db24f7aafe64897e4e659ffbb7d","Linux >= a9e10e58730432e5de840eb3ddd55c75f29341b3 < 428a82d987fcd8844e8868c85582eae75b4b5c51","Linux >= a9e10e58730432e5de840eb3ddd55c75f29341b3 < 2b3a5dabe89e330413af403246b648c1890f368f","Linux 5.14"],"published":"2026-09-17","updated":"2026-09-17","sourceUpdated":"2026-09-17T17:18:05.943","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93114","references":[{"url":"https://git.kernel.org/stable/c/2b3a5dabe89e330413af403246b648c1890f368f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3855be0100efb98c26228c610db70a673611f3bd","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/428a82d987fcd8844e8868c85582eae75b4b5c51","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4faa43d4ef0b98beb6c2b77a279f4aa5d7fa2d13","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7fea5a310e3b2db24f7aafe64897e4e659ffbb7d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b6479da662c2ec4e931ed9f7228df46aa8c3766","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f276b62f2ce1cbff7fa50a8ee5afd8fef5a60897","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-17T16:21:47.753Z","epss":0.00172,"epssPercentile":0.05828,"slug":"CVE-2026-93114","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nplatform/surface: acpi-notify: Check ACPI companion before use\n\nSince every platform driver can be forced to match a device that doesn't\nmatch its list of device IDs because of device_match_driver_override(),\nplatform drivers that rely on the existence of a device's ACPI companion\nobject should verify its presence.\n\nsan_probe() dereferences the result of ACPI_COMPANION() when installing\nthe GSBUS address space handler, so force-binding the driver to a device\nwithout an ACPI companion leads to a NULL pointer dereference.  The\ndereference was introduced when the probe function was switched from\nACPI_HANDLE() to ACPI_COMPANION().\n\nCheck the ACPI companion against NULL and return -ENODEV when it is\nmissing, like commit e4865a56d013 (\"ACPI: driver: Check ACPI_COMPANION()\nagainst NULL during probe\") does for the core ACPI platform drivers.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}