Executive brief
The ASUS wireless driver in the Linux kernel could be forced to bind to incompatible devices, resulting in a NULL pointer dereference when the driver is unbound. This causes a system crash or denial of service. The issue affects systems using the ASUS wireless driver when administrative tools forcibly bind the driver to mismatched hardware.
Technical details
The vulnerability is a NULL pointer dereference in the asus-wireless platform driver probe and remove functions. The root cause is improper validation of ACPI device matching: asus_wireless_probe() did not validate that the device actually matched the driver's ID table before proceeding, and stored a NULL ACPI companion pointer. When asus_wireless_remove() later called acpi_dev_remove_notify_handler() with this NULL pointer, it triggered a crash. The attack vector requires local administrative access to force driver binding via device_match_driver_override(). The fix validates ACPI device matching early in probe, before allocating driver state, and returns -ENODEV if no match is found.
Affected products
- Linux Linux kernel all versions with asus-wireless driver; fix included in 6.11 stable and later
Timeline
- 2026-07-10: other: Patch committed by Linmao Li
- 2026-09-17: disclosed