Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound

Summary

CVECVE-2026-98202
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-10-06 09:18:06 UTC
Updated2026-10-06 09:18:06 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound Transport drivers (such as rmi_i2c and rmi_spi) invoke rmi_driver_suspend() and rmi_driver_resume() on their child rmi_dev device during system power management events. However, transport drivers are fully registered and operational even if the physical RMI driver failed to bind or probe the rmi_dev device. When rmi_driver_suspend() or rmi_driver_resume() is called on an unbound rmi_dev, dev_get_drvdata() returns NULL. Calling rmi_disable_irq() or rmi_enable_irq() without driver data attached causes a NULL pointer dereference and General Protection Fault when attempting to lock data->enabled_mutex. Fix this by checking if driver data is attached to rmi_dev in rmi_driver_suspend() and rmi_driver_resume(), exiting early if no driver data is present.

Risk And Classification

EPSS: 0.001840000 probability, percentile 0.073020000 (date 2026-10-06)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 2b6a321da9a2d8725a1d3dbb0b2e96a7618ebe56 7a3d7c68aa36f68e2a4824da4782c0e5d7c4eba4 git Not specified
CNA Linux Linux affected 2b6a321da9a2d8725a1d3dbb0b2e96a7618ebe56 fafca210631d8c2d4311bdfccc5ec46b9fe65977 git Not specified
CNA Linux Linux affected 2b6a321da9a2d8725a1d3dbb0b2e96a7618ebe56 84145a4a1dc58f8959811913c5f61f3235dd9f6c git Not specified
CNA Linux Linux affected 2b6a321da9a2d8725a1d3dbb0b2e96a7618ebe56 e2b6703465c1ce43edb91c1626604b7092b3c431 git Not specified
CNA Linux Linux affected 2b6a321da9a2d8725a1d3dbb0b2e96a7618ebe56 30366f507ce3e408caf7f7375bb343df54b9a4f9 git Not specified
CNA Linux Linux affected 2b6a321da9a2d8725a1d3dbb0b2e96a7618ebe56 fa1713dc3d43d028d6cb66e5659d9d7e83b73362 git Not specified
CNA Linux Linux affected 2b6a321da9a2d8725a1d3dbb0b2e96a7618ebe56 942b06a19252908d0f952c0590caf20e47f88252 git Not specified
CNA Linux Linux affected 2b6a321da9a2d8725a1d3dbb0b2e96a7618ebe56 fe10579b6dc3f0dac61e51e1797cacbba5039ac2 git Not specified
CNA Linux Linux affected 4.6 Not specified
CNA Linux Linux unaffected 4.6 semver Not specified
CNA Linux Linux unaffected 5.10.271 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.222 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.189 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.158 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.112 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.54 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.8 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc4 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/fa1713dc3d43d028d6cb66e5659d9d7e83b73362 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/e2b6703465c1ce43edb91c1626604b7092b3c431 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/7a3d7c68aa36f68e2a4824da4782c0e5d7c4eba4 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/fe10579b6dc3f0dac61e51e1797cacbba5039ac2 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/84145a4a1dc58f8959811913c5f61f3235dd9f6c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/942b06a19252908d0f952c0590caf20e47f88252 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/30366f507ce3e408caf7f7375bb343df54b9a4f9 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/fafca210631d8c2d4311bdfccc5ec46b9fe65977 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report