ACPI Device Management Vulnerability in Linux Kernel
CVE-2026-100072
Currently unrated
What is CVE-2026-100072?
A vulnerability in the Linux kernel's ACPI subsystem has been identified that poses risks related to improper device management and resource allocation. The use of acpi_get_first_physical_node() within critical functions was deemed unsafe, as it could return a device that might be freed unexpectedly. Furthermore, this approach led to inefficiencies since the same function was called multiple times for the same input. Resolution involves replacing this outdated function with acpi_bus_get_primary_device() to improve reliability and performance, ensuring it is invoked only once during device creation.
Affected Version(s)
Linux 3b95bd160547f56a68aeb972c33ae9511e7a8380
Linux 3b95bd160547f56a68aeb972c33ae9511e7a8380
Linux 4.6