Answer in brief
CVE-2026-93115 records a Unknown severity vulnerability in platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1a218d312e65ec396b2739056a8ea78493015f21 <950d8e8375f3ff4787de51b7bdf8dd23a3ad6547 || >=1a218d312e65ec396b2739056a8ea78493015f21 <fdfb736282b9665c0169df0c4152ec91fdea2767 || >=1a218d312e65ec396b2739056a8ea78493015f21 <bf1e0cc5cc1d4e71b699fc98cc9198ead0ed53e0 || >=1a218d312e65ec396b2739056a8ea78493015f21 <a75b84119e56fc34b0f1403f3b93d357a55dabb6 || >=1a218d312e65ec396b2739056a8ea78493015f21 <71ba8b6e28f7a83b724036f5de07e03bb5473286 || >=1a218d312e65ec396b2739056a8ea78493015f21 <d25dd08268aeaceb485189aaa84aa6d68a460291 || >=1a218d312e65ec396b2739056a8ea78493015f21 <c38cce70adef874c2a7b5132c14d6c221401deff | 950d8e8375f3ff4787de51b7bdf8dd23a3ad6547, fdfb736282b9665c0169df0c4152ec91fdea2767, bf1e0cc5cc1d4e71b699fc98cc9198ead0ed53e0, a75b84119e56fc34b0f1403f3b93d357a55dabb6, 71ba8b6e28f7a83b724036f5de07e03bb5473286, d25dd08268aeaceb485189aaa84aa6d68a460291, c38cce70adef874c2a7b5132c14d6c221401deff |
| Linux/Linuxgeneric | 5.11 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL Every platform driver can be forced to match a device that doesn't match its list of device IDs because of device_match_driver_override(), so platform drivers that rely on the existence of a device's ACPI companion object need to verify its presence. mlxbf_pmc_probe() passes the result of ACPI_COMPANION() to acpi_device_hid(), which dereferences it, so force-binding the driver to a device without an ACPI companion leads to a NULL pointer dereference. Accordingly, add a requisite ACPI_COMPANION() check against NULL to the mlxbf-pmc driver and return -ENODEV when the companion is missing.
Quoted source text, attributed separately from HOL analysis.