Impact
A NULL pointer dereference can occur during the early runtime suspend callback in the Qualcomm snps‑femto‑v2 PHY driver. During system startup the driver enables runtime PM only if the parent device already has it active. The callback code, however, unconditionally dereferences the hardware Super PHY instance, which may not yet be initialized. If a suspend event is triggered before the PHY is fully created, the driver will crash the kernel, causing a denial of service. This crash is a severe local impact because it results in a kernel panic that destabilizes the entire system. The weakness is a classic NULL pointer dereference and is counted as a runtime PM handling flaw.\nThe likely attack vector is a local user or attacker with elevated privileges who can control the power management state of the parent device or influence the order of PHY creation. The flaw requires the presence of the faulting driver and an opportunity for the suspend callback to execute while the PHY is incomplete, which is realistic in most kernel builds that include this driver. While the CISA KEV flag is not set and the EPSS score is below 1%, the kernel crash remains a high‑impact local threat, especially on systems that rely heavily on Qualcomm firmware and devices.\nRisk and exploitability assessments show that the EPSS score indicates a very low probability of active exploitation. Nevertheless, any successful exploit would lead to a full system reboot or kernel panic, making the vulnerability significant despite its limited exposure. Because it is not currently listed in the KEV catalog, there is no evidence of widespread exploitation, but patching remains the recommended mitigative strategy.
Affected Systems
This vulnerability affects all Linux kernel releases that include the snps‑femto‑v2 PHY driver. The driver is shipped as part of the standard Linux kernel tree, so any distribution kernel that has not yet incorporated the commit fixing the NULL dereference is impacted. The modules affected are the Qualcomm and Synopsys femto‑PHY drivers that rely on runtime PM handling. Vendors that ship unmodified kernels, such as those that use community or upstream sources, will inherit this flaw unless they apply the upstream fix.\nThe CNA identifiers list the Linux kernel as vendor and product, indicating that all builds from this source will be susceptible until the code change is merged.
Risk and Exploitability
The vulnerability carries a denial‑of‑service impact due to an eventual kernel panic from a NULL pointer dereference in a power‑management callback. EPSS predicts less than 1% exploitation probability, and the vulnerability is not in the CISA KEV catalog, suggesting no current widespread exploitation. Attackers would need local or privileged access to manipulate runtime PM state or trigger early suspend. The flaw does not offer a remote code execution or privilege escalation path; it is limited to local kernel crashes. The damage is therefore confined to availability denials on the affected host.
OpenCVE Enrichment
Debian DLA
Debian DSA