CVE-2026-23443

In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: Fix previous acpi_processor_errata_piix4() fix After commi f132e089fe89 ("ACPI: processor: Fix NULL-pointer dereference in acpi_processor_errata_piix4()"), device pointers may be dereferenced after dropping references to the device objects pointed to by them, which may cause a use-after-free to occur. Moreover, debug messages about enabling the errata may be printed if the errata flags corresponding to them are unset. Address all of these issues by moving message printing to the points in the code where the errata flags are set.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15.202:*:*:*:*:*:*:*

History

24 Jul 2026, 21:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: ACPI: processor: Corrige la corrección anterior de acpi_processor_errata_piix4() Después del commit f132e089fe89 ('ACPI: processor: Corrige la desreferenciación de puntero NULL en acpi_processor_errata_piix4()'), los punteros de dispositivo pueden ser desreferenciados después de eliminar las referencias a los objetos de dispositivo a los que apuntan, lo que puede causar un uso después de liberación. Además, los mensajes de depuración sobre la habilitación de las erratas pueden imprimirse si las banderas de errata correspondientes a ellas no están establecidas. Aborda todos estos problemas moviendo la impresión de mensajes a los puntos en el código donde las banderas de errata están establecidas.

23 Apr 2026, 20:58

Type Values Removed Values Added
First Time Linux
Linux linux Kernel
CWE CWE-476
References () https://git.kernel.org/stable/c/2e369ba9eb7b8a06e9cc35a3e7fe73e59272f8c2 - () https://git.kernel.org/stable/c/2e369ba9eb7b8a06e9cc35a3e7fe73e59272f8c2 - Patch
References () https://git.kernel.org/stable/c/68408e8f9e366ad9850a66ac65cb569f13bf6cd4 - () https://git.kernel.org/stable/c/68408e8f9e366ad9850a66ac65cb569f13bf6cd4 - Patch
References () https://git.kernel.org/stable/c/8583f62259e1b315d5239371adfb36939cdab741 - () https://git.kernel.org/stable/c/8583f62259e1b315d5239371adfb36939cdab741 - Patch
References () https://git.kernel.org/stable/c/98473309a36acc271009b85e0bb53a4c0dddf5c2 - () https://git.kernel.org/stable/c/98473309a36acc271009b85e0bb53a4c0dddf5c2 - Patch
References () https://git.kernel.org/stable/c/bf504b229cb8d534eccbaeaa23eba34c05131e25 - () https://git.kernel.org/stable/c/bf504b229cb8d534eccbaeaa23eba34c05131e25 - Patch
References () https://git.kernel.org/stable/c/e0c470049344e9346fff79d7e2362212c216665e - () https://git.kernel.org/stable/c/e0c470049344e9346fff79d7e2362212c216665e - Patch
References () https://git.kernel.org/stable/c/edf4c2aaee08e8fd503fbae705c801e92a0b55d7 - () https://git.kernel.org/stable/c/edf4c2aaee08e8fd503fbae705c801e92a0b55d7 - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:linux:linux_kernel:5.15.202:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

18 Apr 2026, 09:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/68408e8f9e366ad9850a66ac65cb569f13bf6cd4 -

03 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 16:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-23443

Mitre link : CVE-2026-23443

CVE.ORG link : CVE-2026-23443


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference