CVE-2026-93115

Summary

In the Linux kernel, the following vulnerability has been resolved:

platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL

Every platform driver can be forced to match a device that doesn't match its list of device IDs because of device_match_driver_override(), so platform drivers that rely on the existence of a device's ACPI companion object need to verify its presence.

mlxbf_pmc_probe() passes the result of ACPI_COMPANION() to acpi_device_hid(), which dereferences it, so force-binding the driver to a device without an ACPI companion leads to a NULL pointer dereference.

Accordingly, add a requisite ACPI_COMPANION() check against NULL to the mlxbf-pmc driver and return -ENODEV when the companion is missing.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux1a218d312e65ec396b2739056a8ea78493015f21 < 950d8e8375f3ff4787de51b7bdf8dd23a3ad6547affected
LinuxLinux1a218d312e65ec396b2739056a8ea78493015f21 < fdfb736282b9665c0169df0c4152ec91fdea2767affected
LinuxLinux1a218d312e65ec396b2739056a8ea78493015f21 < bf1e0cc5cc1d4e71b699fc98cc9198ead0ed53e0affected
LinuxLinux1a218d312e65ec396b2739056a8ea78493015f21 < a75b84119e56fc34b0f1403f3b93d357a55dabb6affected
LinuxLinux1a218d312e65ec396b2739056a8ea78493015f21 < 71ba8b6e28f7a83b724036f5de07e03bb5473286affected
LinuxLinux1a218d312e65ec396b2739056a8ea78493015f21 < d25dd08268aeaceb485189aaa84aa6d68a460291affected
LinuxLinux1a218d312e65ec396b2739056a8ea78493015f21 < c38cce70adef874c2a7b5132c14d6c221401deffaffected
LinuxLinux5.11affected
LinuxLinux0 < 5.11unaffected
LinuxLinux5.15.221 <= 5.15.*unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References