CVE-2026-93251

Source
https://cve.org/CVERecord?id=CVE-2026-93251
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-93251.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-93251
Downstream
Related
Published
2026-09-24T15:51:27Z
Modified
2026-09-29T18:26:50Z
Summary
ACPI: bus: Introduce acpi_bus_get_primary_device()
Details

In the Linux kernel, the following vulnerability has been resolved:

ACPI: bus: Introduce acpi_bus_get_primary_device()

The function used for obtaining the first "physical" device for which the given ACPI one is the ACPI companion, acpi_get_first_physical_node(), may return a stale device pointer (mostly in theory) because acpi_unbind_one() may run as a whole after dropping the ACPI device's physical_node_lock in acpi_get_first_physical_node() and before it returns. The last reference to the "physical" device may be dropped then before the pointer to it is returned to the caller.

If that happens and the acpi_get_first_physical_node() caller invokes get_device() on the pointer obtained from it, which is done by the majority of its callers, a use-after-free will occur.

To prepare for addressing this problem, introduce a new function for getting the first "physical" device associated with the given ACPI one (the "primary physical device") that will also reference count the device in question before returning a pointer to it.

Make that new function and acpi_get_first_physical_node() share the physical node list lookup code.

No intentional functional impact.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93251.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
91e5687805885f9fceb60b95e950a3d3bdcf4764
Fixed
5657859851abb65105220a6cdb5804926249f714
Fixed
72530e1f72b0515a73fd88292254d04fecf03649

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-93251.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.8.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-93251.json"