Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
tpm_crb: Check ACPI_COMPANION() against NULL during probe
Every platform driver can be forced to match a device that doesn’t match its list of device IDs because of device_match_driver_override(), so platform drivers that rely on the existence of a device’s ACPI companion object need to verify its presence.
Accordingly, add a requisite ACPI_COMPANION() check against NULL to the tpm_crb driver.
Details
- Affected product:
- Debian 10 ELS
- Affected packages:
- linux @ 4.19.0