CVE-2026-43313: ACPI: processor: Fix NULL-pointer dereference in acpi_processor_errata_piix4()
In the Linux kernel, the following vulnerability has been resolved:
ACPI: processor: Fix NULL-pointer dereference in acpiprocessorerratapiix4()
In acpiprocessorerratapiix4(), the pointer dev is first assigned an IDE device and then reassigned an ISA device:
dev = pcigetsubsys(..., PCIDEVICEIDINTEL82371AB, ...); dev = pcigetsubsys(..., PCIDEVICEIDINTEL82371AB0, ...);
If the first lookup succeeds but the second fails, dev becomes NULL. This leads to a potential null-pointer dereference when devdbg() is called:
if (errata.piix4.bmisx) devdbg(&dev->dev, ...);
To prevent this, use two temporary pointers and retrieve each device independently, avoiding overwriting dev with a possible NULL value.
[ rjw: Subject adjustment, added an empty code line ]
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-43313?
CVE-2026-43313 has been classified with a medium severity due to the potential for causing a system crash.
How do I fix CVE-2026-43313?
To fix CVE-2026-43313, update the Linux kernel to the latest version that includes the patch addressing the NULL-pointer dereference.
What systems are affected by CVE-2026-43313?
CVE-2026-43313 affects various versions of the Linux kernel utilizing ACPI processor components.
What does CVE-2026-43313 entail?
CVE-2026-43313 entails a NULL-pointer dereference in the acpi_processor_errata_piix4() function that may lead to system instability.
Is CVE-2026-43313 actively exploited?
As of now, there are no known active exploits for CVE-2026-43313 reported in the wild.