CVE-2026-23443
published 2026-04-03CVE-2026-23443: In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: Fix previous acpi_processor_errata_piix4() fix After commi f132e089fe89…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
ACPI: processor: Fix previous acpi_processor_errata_piix4() fix
After commi f132e089fe89 ("ACPI: processor: Fix NULL-pointer dereference
in acpi_processor_errata_piix4()"), device pointers may be dereferenced
after dropping references to the device objects pointed to by them,
which may cause a use-after-free to occur.
Moreover, debug messages about enabling the errata may be printed
if the errata flags corresponding to them are unset.
Address all of these issues by moving message printing to the points
in the code where the errata flags are set.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.19.10-1 (forky) | linux 6.19.10-1 (forky) |
| linux | linux | >= 01e8751b37a366b1ca561add0042f2ceb18c03bf < edf4c2aaee08e8fd503fbae705c801e92a0b55d7 | edf4c2aaee08e8fd503fbae705c801e92a0b55d7 |
| linux | linux | >= 0398b641be2b66c2fc7e0163c606ef19372e7ad5 < 8583f62259e1b315d5239371adfb36939cdab741 | 8583f62259e1b315d5239371adfb36939cdab741 |
| linux | linux | >= 06724a60cfa9767ea90b0f5d3dfb5cdd251b64f5 < 68408e8f9e366ad9850a66ac65cb569f13bf6cd4 | 68408e8f9e366ad9850a66ac65cb569f13bf6cd4 |
| linux | linux | >= 29f60d3d06818d40118a30d663231f027ae87a05 < 98473309a36acc271009b85e0bb53a4c0dddf5c2 | 98473309a36acc271009b85e0bb53a4c0dddf5c2 |
| linux | linux | >= 5.15.202 < 5.15.203 | 5.15.203 |
| linux | linux | >= 6.1.165 < 6.1.167 | 6.1.167 |
| linux | linux | >= 6.12.75 < 6.12.78 | 6.12.78 |
| linux | linux | >= 6.18.16 < 6.18.20 | 6.18.20 |
| linux | linux | >= 6.19.6 < 6.19.10 | 6.19.10 |
| linux | linux | >= 6.6.128 < 6.6.130 | 6.6.130 |
| linux | linux | >= ad86ac604f8391c0212a91412d4f764c7a85f254 < 2e369ba9eb7b8a06e9cc35a3e7fe73e59272f8c2 | 2e369ba9eb7b8a06e9cc35a3e7fe73e59272f8c2 |
| linux | linux | >= b803811485ac0b2f774b6bf3abc8b999ba3b7033 < e0c470049344e9346fff79d7e2362212c216665e | e0c470049344e9346fff79d7e2362212c216665e |
| linux | linux | >= f132e089fe89cadc2098991f0a3cb05c3f824ac6 < bf504b229cb8d534eccbaeaa23eba34c05131e25 | bf504b229cb8d534eccbaeaa23eba34c05131e25 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.19.10-1 | 6.19.10-1 |
| linux | linux_kernel | >= 6.1.165 < 6.1.167 | 6.1.167 |
| linux | linux_kernel | >= 6.12.75 < 6.12.78 | 6.12.78 |
| linux | linux_kernel | >= 6.18.16 < 6.18.20 | 6.18.20 |
| linux | linux_kernel | >= 6.19.6 < 6.19.10 | 6.19.10 |
| linux | linux_kernel | >= 6.6.128 < 6.6.130 | 6.6.130 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 7.0-rc4 acpi_processor_errata_piix4 null pointer dereference (EUVD-2026-18686 / Nessus ID 313522)
vuldb·2026-05-10·CVSS 5.5
CVE-2026-23443 [MEDIUM] Linux Kernel up to 7.0-rc4 acpi_processor_errata_piix4 null pointer dereference (EUVD-2026-18686 / Nessus ID 313522)
A vulnerability was found in Linux Kernel up to 7.0-rc4. It has been rated as critical. Affected is the function acpi_processor_errata_piix4. The manipulation leads to null pointer dereference.
This vulnerability is referenced as CVE-2026-23443. The attack needs to be initiated within the local network. No exploit is available.
Upgrading the affected component is advised.
GHSA
GHSA-gh6m-4cqq-86hr: In the Linux kernel, the following vulnerability has been resolved:
ACPI: processor: Fix previous acpi_processor_errata_piix4() fix
After commi f132
ghsa_unreviewed·2026-04-03
CVE-2026-23443 GHSA-gh6m-4cqq-86hr: In the Linux kernel, the following vulnerability has been resolved:
ACPI: processor: Fix previous acpi_processor_errata_piix4() fix
After commi f132
In the Linux kernel, the following vulnerability has been resolved:
ACPI: processor: Fix previous acpi_processor_errata_piix4() fix
After commi f132e089fe89 ("ACPI: processor: Fix NULL-pointer dereference
in acpi_processor_errata_piix4()"), device pointers may be dereferenced
after dropping references to the device objects pointed to by them,
which may cause a use-after-free to occur.
Moreover, debug messages about enabling the errata may be printed
if the errata flags corresponding to them are unset.
Address all of these issues by moving message printing to the points
in the code where the errata flags are set.
OSV
CVE-2026-23443: In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: Fix previous acpi_processor_errata_piix4() fix After commi f132e0
osv·2026-04-03
CVE-2026-23443 CVE-2026-23443: In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: Fix previous acpi_processor_errata_piix4() fix After commi f132e0
In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: Fix previous acpi_processor_errata_piix4() fix After commi f132e089fe89 ("ACPI: processor: Fix NULL-pointer dereference in acpi_processor_errata_piix4()"), device pointers may be dereferenced after dropping references to the device objects pointed to by them, which may cause a use-after-free to occur. Moreover, debug messages about enabling the errata may be printed if the errata flags corresponding to them are unset. Address all of these issues by moving message printing to the points in the code where the errata flags are set.
Red Hat
kernel: ACPI: processor: Fix previous acpi_processor_errata_piix4() fix
vendor_redhat·2026-04-03
CVE-2026-23443 kernel: ACPI: processor: Fix previous acpi_processor_errata_piix4() fix
kernel: ACPI: processor: Fix previous acpi_processor_errata_piix4() fix
In the Linux kernel, the following vulnerability has been resolved:
ACPI: processor: Fix previous acpi_processor_errata_piix4() fix
After commi f132e089fe89 ("ACPI: processor: Fix NULL-pointer dereference
in acpi_processor_errata_piix4()"), device pointers may be dereferenced
after dropping references to the device objects pointed to by them,
which may cause a use-after-free to occur.
Moreover, debug messages about enabling the errata may be printed
if the errata flags corresponding to them are unset.
Address all of these issues by moving message printing to the points
in the code where the errata flags are set.
A flaw was found in the Linux kernel's ACPI (Advanced Configuration and Power Interface) processor errata
Debian
CVE-2026-23443: linux - In the Linux kernel, the following vulnerability has been resolved: ACPI: proce...
vendor_debian·2026
CVE-2026-23443 [LOW] CVE-2026-23443: linux - In the Linux kernel, the following vulnerability has been resolved: ACPI: proce...
In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: Fix previous acpi_processor_errata_piix4() fix After commi f132e089fe89 ("ACPI: processor: Fix NULL-pointer dereference in acpi_processor_errata_piix4()"), device pointers may be dereferenced after dropping references to the device objects pointed to by them, which may cause a use-after-free to occur. Moreover, debug messages about enabling the errata may be printed if the errata flags corresponding to them are unset. Address all of these issues by moving message printing to the points in the code where the errata flags are set.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.19.10-1)
sid: resolved (fixed in 6.19.10-1)
trixie: resolved
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/2e369ba9eb7b8a06e9cc35a3e7fe73e59272f8c2https://git.kernel.org/stable/c/68408e8f9e366ad9850a66ac65cb569f13bf6cd4https://git.kernel.org/stable/c/8583f62259e1b315d5239371adfb36939cdab741https://git.kernel.org/stable/c/98473309a36acc271009b85e0bb53a4c0dddf5c2https://git.kernel.org/stable/c/bf504b229cb8d534eccbaeaa23eba34c05131e25https://git.kernel.org/stable/c/e0c470049344e9346fff79d7e2362212c216665ehttps://git.kernel.org/stable/c/edf4c2aaee08e8fd503fbae705c801e92a0b55d7
2026-04-03
Published