---
id: CVE-2026-93115
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL

  Every platform driver can be forced to match a device that doesn't match
  its list of device IDs becau…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL

  Every platform driver can be forced to match a device that doesn't match
  its list of device IDs becau…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 1a218d312e65ec396b2739056a8ea78493015f21 <
    950d8e8375f3ff4787de51b7bdf8dd23a3ad6547
  - >-
    Linux >= 1a218d312e65ec396b2739056a8ea78493015f21 <
    fdfb736282b9665c0169df0c4152ec91fdea2767
  - >-
    Linux >= 1a218d312e65ec396b2739056a8ea78493015f21 <
    bf1e0cc5cc1d4e71b699fc98cc9198ead0ed53e0
  - >-
    Linux >= 1a218d312e65ec396b2739056a8ea78493015f21 <
    a75b84119e56fc34b0f1403f3b93d357a55dabb6
  - >-
    Linux >= 1a218d312e65ec396b2739056a8ea78493015f21 <
    71ba8b6e28f7a83b724036f5de07e03bb5473286
  - >-
    Linux >= 1a218d312e65ec396b2739056a8ea78493015f21 <
    d25dd08268aeaceb485189aaa84aa6d68a460291
  - >-
    Linux >= 1a218d312e65ec396b2739056a8ea78493015f21 <
    c38cce70adef874c2a7b5132c14d6c221401deff
  - Linux 5.11
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:18:06.073'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93115'
references:
  - url: 'https://git.kernel.org/stable/c/71ba8b6e28f7a83b724036f5de07e03bb5473286'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/950d8e8375f3ff4787de51b7bdf8dd23a3ad6547'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a75b84119e56fc34b0f1403f3b93d357a55dabb6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bf1e0cc5cc1d4e71b699fc98cc9198ead0ed53e0'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c38cce70adef874c2a7b5132c14d6c221401deff'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d25dd08268aeaceb485189aaa84aa6d68a460291'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fdfb736282b9665c0169df0c4152ec91fdea2767'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.752Z'
epss: 0.00215
epssPercentile: 0.10493
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL

Every platform driver can be forced to match a device that doesn't match
its list of device IDs because of device_match_driver_override(), so
platform drivers that rely on the existence of a device's ACPI companion
object need to verify its presence.

mlxbf_pmc_probe() passes the result of ACPI_COMPANION() to
acpi_device_hid(), which dereferences it, so force-binding the driver to
a device without an ACPI companion leads to a NULL pointer dereference.

Accordingly, add a requisite ACPI_COMPANION() check against NULL to the
mlxbf-pmc driver and return -ENODEV when the companion is missing.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
