PT-2026-106531 · Linux · Linux

CVE-2026-98202

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound
Transport drivers (such as rmi i2c and rmi spi) invoke rmi driver suspend() and rmi driver resume() on their child rmi dev device during system power management events. However, transport drivers are fully registered and operational even if the physical RMI driver failed to bind or probe the rmi dev device.
When rmi driver suspend() or rmi driver resume() is called on an unbound rmi dev, dev get drvdata() returns NULL. Calling rmi disable irq() or rmi enable irq() without driver data attached causes a NULL pointer dereference and General Protection Fault when attempting to lock data->enabled mutex.
Fix this by checking if driver data is attached to rmi dev in rmi driver suspend() and rmi driver resume(), exiting early if no driver data is present.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98202

Affected Products

Linux