Answer in brief
CVE-2026-98202 records a Unknown severity vulnerability in Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=2b6a321da9a2d8725a1d3dbb0b2e96a7618ebe56 <7a3d7c68aa36f68e2a4824da4782c0e5d7c4eba4 || >=2b6a321da9a2d8725a1d3dbb0b2e96a7618ebe56 <fafca210631d8c2d4311bdfccc5ec46b9fe65977 || >=2b6a321da9a2d8725a1d3dbb0b2e96a7618ebe56 <84145a4a1dc58f8959811913c5f61f3235dd9f6c || >=2b6a321da9a2d8725a1d3dbb0b2e96a7618ebe56 <e2b6703465c1ce43edb91c1626604b7092b3c431 || >=2b6a321da9a2d8725a1d3dbb0b2e96a7618ebe56 <30366f507ce3e408caf7f7375bb343df54b9a4f9 || >=2b6a321da9a2d8725a1d3dbb0b2e96a7618ebe56 <fa1713dc3d43d028d6cb66e5659d9d7e83b73362 || >=2b6a321da9a2d8725a1d3dbb0b2e96a7618ebe56 <942b06a19252908d0f952c0590caf20e47f88252 || >=2b6a321da9a2d8725a1d3dbb0b2e96a7618ebe56 <fe10579b6dc3f0dac61e51e1797cacbba5039ac2 | 7a3d7c68aa36f68e2a4824da4782c0e5d7c4eba4, fafca210631d8c2d4311bdfccc5ec46b9fe65977, 84145a4a1dc58f8959811913c5f61f3235dd9f6c, e2b6703465c1ce43edb91c1626604b7092b3c431, 30366f507ce3e408caf7f7375bb343df54b9a4f9, fa1713dc3d43d028d6cb66e5659d9d7e83b73362, 942b06a19252908d0f952c0590caf20e47f88252, fe10579b6dc3f0dac61e51e1797cacbba5039ac2 |
| Linux/Linuxgeneric | 4.6 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound Transport drivers (such as rmi_i2c and rmi_spi) invoke rmi_driver_suspend() and rmi_driver_resume() on their child rmi_dev device during system power management events. However, transport drivers are fully registered and operational even if the physical RMI driver failed to bind or probe the rmi_dev device. When rmi_driver_suspend() or rmi_driver_resume() is called on an unbound rmi_dev, dev_get_drvdata() returns NULL. Calling rmi_disable_irq() or rmi_enable_irq() without driver data attached causes a NULL pointer dereference and General Protection Fault when attempting to lock data->enabled_mutex. Fix this by checking if driver data is attached to rmi_dev in rmi_driver_suspend() and rmi_driver_resume(), exiting early if no driver data is present.
Quoted source text, attributed separately from HOL analysis.