Junglewise Threat Intelligence

CVE-2026-90194: Linux kernel ACPI bus ID cleanup on device_add() failure

CVE-2026-90194 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's ACPI device enumeration subsystem has a resource-cleanup bug that occurs when device registration fails. If a device fails to register after the bus ID tracking has been initialized, the allocated instance number remains consumed and bookkeeping entries are not properly removed, potentially leading to resource exhaustion or device enumeration issues on subsequent boot attempts.

Technical details

This is a resource-cleanup defect in the ACPI device scanning code (drivers/acpi/scan.c). When acpi_device_add() fails after acpi_device_set_name() has allocated an instance ID and linked a new acpi_device_bus_id into acpi_bus_id_list, the error path only removes the wakeup_list and detaches ACPI handle data, leaving bus-ID bookkeeping orphaned and the instance number permanently consumed. The fix refactors the cleanup logic into a shared helper function acpi_device_cleanup() that properly cleans up both the bus ID list and wakeup list, and applies it uniformly to both the normal device teardown path and the device_add() error path. No network vector or attacker interaction is involved; this is a kernel internal defect affecting device enumeration reliability.

Affected products

  • Linux Linux kernel Multiple versions from 2.6.11 through 7.2 (see stable branches in advisory)

Timeline

  • 2026-09-17: disclosed
  • 2026-09-14: patched: Upstream commit a414485ebc2aa50907d0ce97cde2b1a353696897; backported to stable branches

References

Related threats