Impact
A NULL‑pointer dereference occurs in the Qualcomm QMP USB PHY driver during an early runtime suspend or resume callback. The driver dereferences qmp->phy before the infrastructure has initialized the pointer, resulting in a kernel crash. This crash can be triggered by a timing window between pm_runtime_enable and pm_runtime_forbid, or by a user re‑enabling runtime‑PM via sysfs before the PHY is initialized. The crash leads to a kernel panic, causing a denial‑of‑service to the affected system.
Affected Systems
All Linux kernel builds that include the Qualcomm QMP USB PHY driver and have not yet been updated with the patch that protects against the NULL dereference. The fix is specific to the qmp‑usb PHY driver within the Linux kernel and applies to all versions prior to the commit containing the change.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of widespread exploitation in the current environment. However, the flaw can be triggered by an attacker with the ability to influence system power‑management, such as through local sysfs access or by precipitating a race condition with runtime‑PM. The risk is therefore a low‑to‑medium likelihood of local, privileged exploitation that would lead to a system crash. The CVSS score is not provided in the available data, but the impact remains a denial‑of‑service when triggered.
OpenCVE Enrichment
Debian DLA
Debian DSA