CVE-2026-89933
Description
In the Linux kernel, the following vulnerability has been resolved: iio: pressure: dps310: fix NULL pointer dereference on ACPI probe When the device is enumerated through its ACPI HID (IFX3100), i2c_client_get_device_id() returns NULL: the ACPI-derived client name does not match the driver's i2c_device_id table. dps310_probe() then dereferences that NULL pointer in "iio->name = id->name" and crashes the kernel during probe. The IIO device name is always "dps310", so set it directly and drop the now-unused device-id lookup.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://git.kernel.org/stable/c/26e9213898fc949923188ef0aeea31fc87708836
- https://git.kernel.org/stable/c/3fa189573cca284ae663bfd2d5b9ed755bec5e9d
- https://git.kernel.org/stable/c/7ded5b76ec2df6a3fb1bfde0d1869cde363fef30
- https://git.kernel.org/stable/c/a32a39da18e01b20c2ab65af9be34dc870187382
- https://git.kernel.org/stable/c/bc7b09e701b4175fc683b579fcdef3bfac809239
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.