HomeDefectsLIN1022-36422
Fixed

LIN1022-36422 : Security Advisory - linux - CVE-2026-89933

Created: Oct 7, 2026    Updated: Oct 8, 2026
Resolved Date: Oct 7, 2026
Found In Version: 10.22.33.2
Fix Version: 10.22.33.11
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  iio: pressure: dps310: fix NULL pointer dereference on ACPI probe  When the device is enumerated through its ACPI HID (IFX3100), i2c_client_get_device_id() returns NULL: the ACPI-derived client name does not match the driver's i2c_device_id table. dps310_probe() then dereferences that NULL pointer in iio->name = id->name and crashes the kernel during probe.  The IIO device name is always dps310, so set it directly and drop the now-unused device-id lookup.