CVE-2026-72432

Summary

In the Linux kernel, the following vulnerability has been resolved:

tpm_crb: Check ACPI_COMPANION() against NULL during probe

Every platform driver can be forced to match a device that doesn't match its list of device IDs because of device_match_driver_override(), so platform drivers that rely on the existence of a device's ACPI companion object need to verify its presence.

Accordingly, add a requisite ACPI_COMPANION() check against NULL to the tpm_crb driver.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux48fe2cddc85c7849463bd01ae8b8c6b575ff508b < c041d2be785feb9b5e36331921eadaefbe65349daffected
LinuxLinux48fe2cddc85c7849463bd01ae8b8c6b575ff508b < ddd33806b8911fa2ef849e8bbbab1e3fcb26adc0affected
LinuxLinux7.1affected
LinuxLinux0 < 7.1unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References