CVE-2026-90194 PUBLISHED

ACPI: scan: fix bus ID cleanup on device_add() failures

Assigner: Linux
Reserved: 11.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

ACPI: scan: fix bus ID cleanup on device_add() failures

When device_add() fails after acpi_device_set_name() has allocated an instance ID and a new acpi_device_bus_id has been linked into acpi_bus_id_list, the rollback path only removes wakeup_list and detaches the ACPI handle data.

That leaves the bus-ID bookkeeping behind and keeps the allocated instance number consumed.

Move the bus-ID cleanup and wakeup-list removal into a single helper.

Use it from both the normal device teardown path and the device_add() rollback path. The wakeup list node is initialized before registration, so it can be deleted without checking whether the device is wakeup- capable like in the original teardown path.

[ rjw: Rename acpi_device_del_list() to acpi_device_cleanup() ] [ rjw: Subject and changelog edits ]

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from d783156ea38431b20af0d4f910a6f9f9054d33b9 to 8cc2017aa804f157e717b5fd471e50fbddfec654 (excl.)
  • affected from d783156ea38431b20af0d4f910a6f9f9054d33b9 to f30379b8a4e24623594235dd5aefb2957e0cc228 (excl.)
  • affected from d783156ea38431b20af0d4f910a6f9f9054d33b9 to 83ee65feadc88de681abc6e977d54eceda95abd7 (excl.)
  • affected from d783156ea38431b20af0d4f910a6f9f9054d33b9 to 15512c6b5dea72fb5f1f41c1aa96f3f32531ca03 (excl.)
  • affected from d783156ea38431b20af0d4f910a6f9f9054d33b9 to 0b9053cd0955c7cd66d71a8442be33926d70e197 (excl.)
  • affected from d783156ea38431b20af0d4f910a6f9f9054d33b9 to a414485ebc2aa50907d0ce97cde2b1a353696897 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 3.14 is affected
  • unaffected from 0 to 3.14 (excl.)
  • unaffected from 6.1.188 to 6.1.* (incl.)
  • unaffected from 6.6.157 to 6.6.* (incl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References