Description
In the Linux kernel, the following vulnerability has been resolved:

phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend

Runtime PM must be enabled before creating the PHY, since phy_create()
only enables runtime PM on the PHY device if it is already enabled on
this parent device. However, the runtime PM callbacks dereference the
hsphy instance, which is not yet ready, leaving a window where a suspend
callback may trigger a NULL pointer dereference.

Take a runtime PM usage reference with pm_runtime_get_noresume() before
enabling runtime PM and release it once the PHY has been created, so that
no runtime suspend can run before the PHY is ready. This also prevents a
short window where an unnecessary runtime suspend can occur.

Use the devres-managed version to ensure PM runtime is symmetrically
disabled during driver removal for proper cleanup.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

A NULL pointer dereference can occur during the early runtime suspend callback in the Qualcomm snps‑femto‑v2 PHY driver. During system startup the driver enables runtime PM only if the parent device already has it active. The callback code, however, unconditionally dereferences the hardware Super PHY instance, which may not yet be initialized. If a suspend event is triggered before the PHY is fully created, the driver will crash the kernel, causing a denial of service. This crash is a severe local impact because it results in a kernel panic that destabilizes the entire system. The weakness is a classic NULL pointer dereference and is counted as a runtime PM handling flaw.\nThe likely attack vector is a local user or attacker with elevated privileges who can control the power management state of the parent device or influence the order of PHY creation. The flaw requires the presence of the faulting driver and an opportunity for the suspend callback to execute while the PHY is incomplete, which is realistic in most kernel builds that include this driver. While the CISA KEV flag is not set and the EPSS score is below 1%, the kernel crash remains a high‑impact local threat, especially on systems that rely heavily on Qualcomm firmware and devices.\nRisk and exploitability assessments show that the EPSS score indicates a very low probability of active exploitation. Nevertheless, any successful exploit would lead to a full system reboot or kernel panic, making the vulnerability significant despite its limited exposure. Because it is not currently listed in the KEV catalog, there is no evidence of widespread exploitation, but patching remains the recommended mitigative strategy.

Affected Systems

This vulnerability affects all Linux kernel releases that include the snps‑femto‑v2 PHY driver. The driver is shipped as part of the standard Linux kernel tree, so any distribution kernel that has not yet incorporated the commit fixing the NULL dereference is impacted. The modules affected are the Qualcomm and Synopsys femto‑PHY drivers that rely on runtime PM handling. Vendors that ship unmodified kernels, such as those that use community or upstream sources, will inherit this flaw unless they apply the upstream fix.\nThe CNA identifiers list the Linux kernel as vendor and product, indicating that all builds from this source will be susceptible until the code change is merged.

Risk and Exploitability

The vulnerability carries a denial‑of‑service impact due to an eventual kernel panic from a NULL pointer dereference in a power‑management callback. EPSS predicts less than 1% exploitation probability, and the vulnerability is not in the CISA KEV catalog, suggesting no current widespread exploitation. Attackers would need local or privileged access to manipulate runtime PM state or trigger early suspend. The flaw does not offer a remote code execution or privilege escalation path; it is limited to local kernel crashes. The damage is therefore confined to availability denials on the affected host.

Generated by OpenCVE AI on September 19, 2026 at 14:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the system to a Linux kernel version that includes the commit that corrects the NULL pointer dereference in the snps‑femto‑v2 PHY driver.
  • If an immediate kernel upgrade is not feasible, modify the driver code to acquire runtime PM with pm_runtime_get_noresume() before enabling runtime PM, release the reference after the PHY is fully created, and employ the devres‑managed approach to guarantee symmetric disabling during driver removal.
  • Ensure that runtime PM is enabled on all parent devices before any PHY instances are created, so the callback cannot run while the PHY is uninitialized.

Generated by OpenCVE AI on September 19, 2026 at 14:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend Runtime PM must be enabled before creating the PHY, since phy_create() only enables runtime PM on the PHY device if it is already enabled on this parent device. However, the runtime PM callbacks dereference the hsphy instance, which is not yet ready, leaving a window where a suspend callback may trigger a NULL pointer dereference. Take a runtime PM usage reference with pm_runtime_get_noresume() before enabling runtime PM and release it once the PHY has been created, so that no runtime suspend can run before the PHY is ready. This also prevents a short window where an unnecessary runtime suspend can occur. Use the devres-managed version to ensure PM runtime is symmetrically disabled during driver removal for proper cleanup.
Title phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:11.916Z

Reserved: 2026-09-11T19:38:34.797Z

Link: CVE-2026-90281

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:24.810

Modified: 2026-09-17T17:17:24.810

Link: CVE-2026-90281

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:45:14Z

Weaknesses