Junglewise Threat Intelligence

CVE-2026-93133: Linux kernel ACPI RISC-V uninitialized variable in riscv_acpi_add_prt_dep()

CVE-2026-93133 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's ACPI RISC-V implementation contains a bug in device dependency resolution where an uninitialized variable could be used if a function call fails. This could cause memory corruption or system crashes when processing ACPI device configurations on RISC-V platforms. While classified as informational severity, the bug presents a stability risk during boot or device initialization.

Technical details

The vulnerability is an uninitialized variable bug (CWE-908) in the riscv_acpi_add_prt_dep() function in drivers/acpi/riscv/irq.c. The acpi_get_handle() function call can fail, but its return status was not being checked, leaving the link_handle variable uninitialized. Downstream code would then use this uninitialized variable, leading to use-of-uninitialized-memory. The fix adds a status check after acpi_get_handle() and skips the current entry if the call fails. This is kernel code executed with full system privileges during boot/device probing, affecting only RISC-V systems running the affected kernel versions. A patch is available and has been merged upstream.

Affected products

  • Linux Linux kernel Kernel versions prior to commit 20435bda13f1219891ed0ce41207e320a916ff9c

Timeline

  • 2026-07-09: disclosed
  • 2026-07-09: patched

References

Related threats