CVE-2026-93128

high

Description

In the Linux kernel, the following vulnerability has been resolved: platform/x86: lg-laptop: Fix LED resource handling The event notification callback might access kbd_backlight even when it was not successfully registered with the LED subsystem. The same happens inside acpi_remove(), where the LED devices are unregistered unconditionally. Fix this by tracking the availability of the kbd_backlight LED device and use devm_led_classdev_register() to let devres take care of unregistering the LED devices during removal. For this the parent device of the LED devices is changed to the native platform device.

References

https://git.kernel.org/stable/c/acc190322250562d5f28860f4ae1ebaf3e304fc2

https://git.kernel.org/stable/c/9a85e2d35e54248aca39bad4f4152ed34de1995f

https://git.kernel.org/stable/c/4fbfe3714f645b6c64c9ba8faa83b27e4c9f2edd

https://git.kernel.org/stable/c/3e91964aa74ab261aa15d9d96318eded2fd9d22a

Details

Source: Mitre, NVD

Published: 2026-09-17

Updated: 2026-09-17

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity: High

EPSS

EPSS: 0.002