CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's bitland-mifs-wmi driver, specifically during the suspend/resume operations, where a NULL pointer dereference can occur due to an uninitialized platform profile device. This flaw can lead to a kernel Oops, causing the system to halt during the suspend sequence. Organizations using affected Linux distributions should prioritize patching this vulnerability to maintain system stability and prevent potential disruptions.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: platform/x86: bitland-mifs-wmi: Fix NULL pointer dereference during suspend/resume The driver registers two distinct WMI devices: a control device (BITLAND_WMI_CONTROL) and an event device (BITLAND_WMI_EVENT). During the probe phase, the event device handling path returns early before initializing the platform profile device (data->pp_dev), leaving it NULL. However, the PM sleep operations are registered globally for the WMI driver and are triggered for both devices. When entering suspend, the event device invokes bitland_mifs_wmi_suspend(), which passes the uninitialized data->pp_dev (NULL) into laptop_profile_get(). This leads to a NULL pointer dereference inside dev_get_drvdata(), causing a kernel Oops and halting the suspend sequence. Fix this by adding a validity check for data->pp_dev in both the suspend and resume callbacks, safely skipping profile operations for the event device.