CVE-2026-93128

Summary

In the Linux kernel, the following vulnerability has been resolved:

platform/x86: lg-laptop: Fix LED resource handling

The event notification callback might access kbd_backlight even when it was not successfully registered with the LED subsystem. The same happens inside acpi_remove(), where the LED devices are unregistered unconditionally.

Fix this by tracking the availability of the kbd_backlight LED device and use devm_led_classdev_register() to let devres take care of unregistering the LED devices during removal. For this the parent device of the LED devices is changed to the native platform device.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxae26278829a80ad0e60ff004de71e9276cee5dc0 < 4fbfe3714f645b6c64c9ba8faa83b27e4c9f2eddaffected
LinuxLinuxae26278829a80ad0e60ff004de71e9276cee5dc0 < 9a85e2d35e54248aca39bad4f4152ed34de1995faffected
LinuxLinuxae26278829a80ad0e60ff004de71e9276cee5dc0 < acc190322250562d5f28860f4ae1ebaf3e304fc2affected
LinuxLinuxae26278829a80ad0e60ff004de71e9276cee5dc0 < 3e91964aa74ab261aa15d9d96318eded2fd9d22aaffected
LinuxLinux5.15affected
LinuxLinux0 < 5.15unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References