CVE-2026-64227

Summary

In the Linux kernel, the following vulnerability has been resolved:

ACPI: driver: Check ACPI_COMPANION() against NULL during probe

Since every platform driver can be forced to match a device that doesn't match its list of device IDs because of device_match_driver_override(), platform drivers that rely on the existence of a device's ACPI companion object should verify its presence.

Accordingly, add requisite ACPI_COMPANION() or ACPI_HANDLE() checks against NULL to 13 platform drivers handling core ACPI devices.

Also change the value returned by the ACPI thermal zone driver when the device's ACPI companion is not present to -ENODEV for consistency with the other drivers.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux5829046825ac89fffc60f2670bc564fda2c0155a < a9451bf561232314755baf69a5916e0ac77f33fcaffected
LinuxLinux5829046825ac89fffc60f2670bc564fda2c0155a < 34f4d0e4e5065237d15651df759a99e81b7f9f51affected
LinuxLinux5829046825ac89fffc60f2670bc564fda2c0155a < 612ddab8fce04394bd7aebe8e0f2599642e30859affected
LinuxLinux5829046825ac89fffc60f2670bc564fda2c0155a < e4865a56d013e86e46ea6acea15bb6eae01898ffaffected
LinuxLinux6.7affected
LinuxLinux0 < 6.7unaffected
LinuxLinux6.12.97 <= 6.12.*unaffected
LinuxLinux6.18.40 <= 6.18.*unaffected
LinuxLinux7.0.11 <= 7.0.*unaffected
LinuxLinux7.1 <= *unaffected

Weaknesses

References