Junglewise Threat Intelligence

CVE-2026-92521: Linux kernel ACPI PCI use-after-free in driver_data

CVE-2026-92521 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's ACPI PCI driver fails to properly clear device pointers when freeing internal data structures during error conditions and device removal. This leaves dangling references that can be dereferenced by subsequent code, potentially causing system crashes or undefined behavior. The issue affects systems that hot-plug PCI devices or encounter ACPI initialization failures.

Technical details

This is a use-after-free vulnerability in the ACPI PCI root device driver (drivers/acpi/pci_root.c). The acpi_pci_root_add() function assigns a newly allocated root structure to device->driver_data, but when dmar_device_add() or pci_acpi_scan_root() fail, the memory is freed without clearing the driver_data pointer in all code paths. Similarly, acpi_pci_root_remove() frees the root structure without clearing driver_data. A subsequent call to acpi_pci_find_root() may dereference the dangling pointer, leading to a kernel crash or potential memory corruption. The fix moves the driver_data NULL assignment to a shared error exit path and adds it to the remove function, ensuring the pointer is always cleared before freeing the structure. No special privileges or network access are required; the issue can be triggered during normal PCI hot-add operations or device removal.

Affected products

  • Linux Linux kernel multiple versions (fix available in stable series)

Timeline

  • 2026-09-17: disclosed: CVE-2026-92521 published
  • 2026-09-14: patched: Patch committed to stable Linux kernel trees

References

Related threats