Description
In the Linux kernel, the following vulnerability has been resolved:

phy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early runtime suspend

There is a small window where the runtime suspend callback may run
after pm_runtime_enable() and before pm_runtime_forbid(). In this
case, a crash occurs because runtime suspend/resume dereferences
qmp->phy pointer, which is not yet initialized:
`if (!qmp->phy->init_count) {`

This can also happen if user re-enables runtime-pm via the sysfs
attribute before qmp phy is initialized.

Similarly to other qcom phy drivers, introduce a qmp->phy_initialized
variable that can be used to avoid relying on the possibly uninitialized
phy pointer.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel crash
Action: Patch Immediately
AI Analysis

Impact

A timing gap exists in the Linux kernel’s Qualcomm QMP USB legacy driver where the runtime suspend handler may execute before the driver’s phy pointer is fully initialized. The handler dereferences this pointer, triggering a null‑pointer crash that brings down the kernel. The resulting denial of service could affect any user or system relying on the affected hardware when runtime power management is enabled.

Affected Systems

The vulnerability applies to any Linux kernel that includes the qcom qmp‑usb‑legacy phy driver. No specific kernel releases or distribution versions are listed, so all standard kernel builds that haven't applied the referenced patch are potentially affected.

Risk and Exploitability

The EPSS value of less than 1 % and the absence from CISA’s KEV catalog suggest that exploitation is unlikely at this time. However, if an attacker can trigger a runtime suspend before the phy is prepared—possible for local users with sufficient privileges or through specialized scripts—the crash can be repeated at will. Because it leads to a complete system halt, the impact remains high even though the likelihood is low. No CVSS score is provided, so an exact severity rating can not be calculated, but the potential for a kernel‑level denial of service keeps the risk non‑negligible for affected deployments.

Generated by OpenCVE AI on September 19, 2026 at 04:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that introduces the qmp->phy_initialized guard as committed in the linked kernel revisions
  • If the patch cannot be applied immediately, disable runtime power management for the QMP USB legacy devices via the corresponding sysfs attributes or by preventing pm_runtime_enable() until initialization completes
  • Monitor system logs for fatal crashes linked to the qmp driver and adjust runtime suspension policies accordingly

Generated by OpenCVE AI on September 19, 2026 at 04:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early runtime suspend There is a small window where the runtime suspend callback may run after pm_runtime_enable() and before pm_runtime_forbid(). In this case, a crash occurs because runtime suspend/resume dereferences qmp->phy pointer, which is not yet initialized: `if (!qmp->phy->init_count) {` This can also happen if user re-enables runtime-pm via the sysfs attribute before qmp phy is initialized. Similarly to other qcom phy drivers, introduce a qmp->phy_initialized variable that can be used to avoid relying on the possibly uninitialized phy pointer.
Title phy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early runtime suspend
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:12.681Z

Reserved: 2026-09-11T19:38:34.797Z

Link: CVE-2026-90282

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:24.950

Modified: 2026-09-17T17:17:24.950

Link: CVE-2026-90282

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T09:15:14Z

Weaknesses