Impact
A timing gap exists in the Linux kernel’s Qualcomm QMP USB legacy driver where the runtime suspend handler may execute before the driver’s phy pointer is fully initialized. The handler dereferences this pointer, triggering a null‑pointer crash that brings down the kernel. The resulting denial of service could affect any user or system relying on the affected hardware when runtime power management is enabled.
Affected Systems
The vulnerability applies to any Linux kernel that includes the qcom qmp‑usb‑legacy phy driver. No specific kernel releases or distribution versions are listed, so all standard kernel builds that haven't applied the referenced patch are potentially affected.
Risk and Exploitability
The EPSS value of less than 1 % and the absence from CISA’s KEV catalog suggest that exploitation is unlikely at this time. However, if an attacker can trigger a runtime suspend before the phy is prepared—possible for local users with sufficient privileges or through specialized scripts—the crash can be repeated at will. Because it leads to a complete system halt, the impact remains high even though the likelihood is low. No CVSS score is provided, so an exact severity rating can not be calculated, but the potential for a kernel‑level denial of service keeps the risk non‑negligible for affected deployments.
OpenCVE Enrichment
Debian DLA
Debian DSA