CVE-2026-89822

medium

Description

In the Linux kernel, the following vulnerability has been resolved: drm/i915: Guard against NULL driver_data in i915_pci_probe() pci_match_device() can return the dummy pci_device_id_any entry when a device is force-bound via sysfs driver_override, in which case ->driver_data is unset (NULL). i915_pci_probe() casts it to struct intel_device_info * unconditionally and dereferences intel_info->require_force_probe, causing a NULL-ptr-deref. (cherry picked from commit 2727922084672cc274ecea726ea00363c2893731)

References

https://git.kernel.org/stable/c/e351cb2d373f6f1d4f1eb7c9f30dc058c69c89f8

https://git.kernel.org/stable/c/84829e324a396668ceafb14723293b2863a74dcf

https://git.kernel.org/stable/c/4a0236fe97732e31cb4a6dcb433642f9e3ef9a56

https://git.kernel.org/stable/c/3785d40831ba5601296283e0197e10e089392757

https://git.kernel.org/stable/c/2239e6b49d33bb38817d69b4f0bf7d5cbde2ec68

https://git.kernel.org/stable/c/18b3433f10ee9c69e3252046028aa2be421f2d4d

Details

Source: Mitre, NVD

Published: 2026-09-16

Updated: 2026-09-17

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00206