Description
In the Linux kernel, the following vulnerability has been resolved:

phy: qcom: qmp-usb: Fix possible NULL-deref on early runtime suspend

There is a small window where the runtime suspend callback may run
after pm_runtime_enable() and before pm_runtime_forbid(). In this
case, a crash occurs because runtime suspend/resume dereferences
qmp->phy pointer, which is not yet initialized:
`if (!qmp->phy->init_count) {`

This can also happen if user re-enables runtime-pm via the sysfs
attribute before qmp phy is initialized.

Similarly to other qcom phy drivers, introduce a qmp->phy_initialized
variable that can be used to avoid relying on the possibly uninitialized
phy pointer.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A NULL‑pointer dereference occurs in the Qualcomm QMP USB PHY driver during an early runtime suspend or resume callback. The driver dereferences qmp->phy before the infrastructure has initialized the pointer, resulting in a kernel crash. This crash can be triggered by a timing window between pm_runtime_enable and pm_runtime_forbid, or by a user re‑enabling runtime‑PM via sysfs before the PHY is initialized. The crash leads to a kernel panic, causing a denial‑of‑service to the affected system.

Affected Systems

All Linux kernel builds that include the Qualcomm QMP USB PHY driver and have not yet been updated with the patch that protects against the NULL dereference. The fix is specific to the qmp‑usb PHY driver within the Linux kernel and applies to all versions prior to the commit containing the change.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of widespread exploitation in the current environment. However, the flaw can be triggered by an attacker with the ability to influence system power‑management, such as through local sysfs access or by precipitating a race condition with runtime‑PM. The risk is therefore a low‑to‑medium likelihood of local, privileged exploitation that would lead to a system crash. The CVSS score is not provided in the available data, but the impact remains a denial‑of‑service when triggered.

Generated by OpenCVE AI on September 19, 2026 at 04:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to include the patch that protects the QMP USB PHY driver from the NULL pointer dereference.
  • If an immediate kernel upgrade is not feasible, disable runtime‑PM for the QMP USB device by removing the driver module or by writing "0" to the appropriate sysfs sysfs attribute, ensuring the PHY is not suspended during use.
  • As a secondary protective measure, restrict write access to the sysfs runtime‑PM attributes to privileged users to mitigate accidental or malicious enabling of runtime‑PM before initialization.

Generated by OpenCVE AI on September 19, 2026 at 04:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usb: Fix possible NULL-deref on early runtime suspend There is a small window where the runtime suspend callback may run after pm_runtime_enable() and before pm_runtime_forbid(). In this case, a crash occurs because runtime suspend/resume dereferences qmp->phy pointer, which is not yet initialized: `if (!qmp->phy->init_count) {` This can also happen if user re-enables runtime-pm via the sysfs attribute before qmp phy is initialized. Similarly to other qcom phy drivers, introduce a qmp->phy_initialized variable that can be used to avoid relying on the possibly uninitialized phy pointer.
Title phy: qcom: qmp-usb: Fix possible NULL-deref on early runtime suspend
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:11.281Z

Reserved: 2026-09-11T19:38:34.797Z

Link: CVE-2026-90280

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:24.690

Modified: 2026-09-17T17:17:24.690

Link: CVE-2026-90280

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T04:30:16Z

Weaknesses