{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-97455","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-24T14:53:16.871Z","datePublished":"2026-09-24T16:04:11.922Z","dateUpdated":"2026-10-03T10:58:39.822Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:58:39.822Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nACPICA: Fix use-after-free in acpi_ds_terminate_control_method()\n\nFix use-after-free issue in acpi_ds_terminate_control_method() by\nclearing references to method locals and arguments."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The data that becomes walk_state->return_desc is AML RefOf(Local/Arg) in the platform DSDT/SSDT. acpi_ex_get_object_reference builds that ACPI_REFCLASS_REFOF; acpi_ps_parse_aml then calls the patched acpi_ds_terminate_control_method from acpi_ns_execute_table (acpi_load_tables) or acpi_ps_execute_method (acpi_evaluate_object). Those tables are local firmware, not a network protocol message.\nAC:L - The table author emits Return(RefOf(LocalN)) or Return(RefOf(ArgN)); acpi_ex_get_object_reference sets reference.object to &walk_state->local_variables[i] or &walk_state->arguments[i]. acpi_ds_terminate_control_method then acpi_ds_method_data_delete_all, acpi_ps_parse_aml still forwards return_desc, and acpi_ds_delete_walk_state frees the node. That sequence is deterministic with no race.\nPR:N - acpi_bus_init calls acpi_load_tables → acpi_tb_load_namespace → acpi_ns_load_table → acpi_ns_execute_table with no uid or capability check. Module-level AML that invokes a nested method returning RefOf(Local/Arg), with the caller Store/DerefOf using that value, hits acpi_ds_terminate_control_method at boot before any account exists.\nUI:N - acpi_ns_execute_table runs that nested Return(RefOf(Local/Arg)) automatically during acpi_load_tables in acpi_bus_init at power-on; the victim does not mount media, open a file, or otherwise interact.\nS:U - The dangling ACPI_REFCLASS_REFOF points at the embedded local_variables[]/arguments[] acpi_namespace_node inside the kmalloc'd acpi_walk_state freed by acpi_ds_delete_walk_state; that is host ACPICA heap corruption, not a KVM/Xen, IOMMU, or sandbox crossing.\nC:H - After acpi_ds_delete_walk_state, acpi_ns_resolve_references reads node->object from the freed local/arg pseudo-node, and a parent DerefOf uses operand[0]->reference.object the same way; that use-after-free of the walk_state slab is an arbitrary kernel-memory read, not a few-byte leak.\nI:H - A parent Store to the returned RefOf calls acpi_ex_store_object_to_node on the dangling node, and acpi_ns_resolve_references does acpi_ut_add_reference on node->object taken from freed walk_state memory; spraying that slab yields a write/refcount primitive and control-flow hijack.\nA:H - acpi_ds_delete_walk_state frees the walk_state while return_desc still aliases its local_variables[]/arguments[] nodes; later ns_resolve_references or DerefOf/Store through that pointer oopses or panics, and any use-after-free is Availability High."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/acpi/acpica/dsmethod.c"],"versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"460aed7b408508a2c28ca4fdd8d90a82bb4005aa","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3855d8992f5a88b033925cc4f6aef7a485f326cb","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2793b1c38f0053fd9b119ce4607dd056eb05d382","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"63ca6f67816a229e07a08cac4bef1b3858abde66","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"fe7b3d3b7490c2c0119f2d84fa33996dcbc71042","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ef5a8d939c1e5b36e75450bbb5b6348faff4dcf3","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"945e87267cfd90937b3c637f87324cbb56998b72","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/acpi/acpica/dsmethod.c"],"versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/460aed7b408508a2c28ca4fdd8d90a82bb4005aa"},{"url":"https://git.kernel.org/stable/c/3855d8992f5a88b033925cc4f6aef7a485f326cb"},{"url":"https://git.kernel.org/stable/c/2793b1c38f0053fd9b119ce4607dd056eb05d382"},{"url":"https://git.kernel.org/stable/c/63ca6f67816a229e07a08cac4bef1b3858abde66"},{"url":"https://git.kernel.org/stable/c/fe7b3d3b7490c2c0119f2d84fa33996dcbc71042"},{"url":"https://git.kernel.org/stable/c/ef5a8d939c1e5b36e75450bbb5b6348faff4dcf3"},{"url":"https://git.kernel.org/stable/c/945e87267cfd90937b3c637f87324cbb56998b72"}],"title":"ACPICA: Fix use-after-free in acpi_ds_terminate_control_method()","x_generator":{"engine":"bippy-1.2.0"}}}}