CVE-2026-89943

high

Description

In the Linux kernel, the following vulnerability has been resolved: ASoC: loongson: Fix error handling in ACPI property parsing In loongson_card_parse_acpi(), the return value of device_property_read_string() for the `codec-dai-name` property was ignored. If the property is missing or invalid, an uninitialized pointer would be used later, potentially leading to undefined behavior. Fix this by checking the return value and propagating the error appropriately.

References

https://git.kernel.org/stable/c/bb1602908c67db7197ab001638573262bccc6ca2

https://git.kernel.org/stable/c/682c123cef455545f48ecbe74b3872fa303bf58f

https://git.kernel.org/stable/c/4e580d84a638f007b5b68d50d7633de502f325e7

https://git.kernel.org/stable/c/0eb0e3c623ac1da8b85d518043fef7660af7805d

Details

Source: Mitre, NVD

Published: 2026-09-16

Updated: 2026-09-16

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.4

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00182