PT-2026-2869 · Linux+3 · Linux Kernel+3
Published
2025-01-01
·
Updated
2026-05-11
·
CVE-2025-71108
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The Linux kernel contains an issue within the USB Type-C UCSI subsystem. The UCSI specification defines the
num connectors field as a 7-bit value, with the 8th bit reserved and required to be zero. Some firmware implementations incorrectly set this 8th bit, potentially preventing the system from booting. The fix involves flagging this incorrect firmware behavior and automatically correcting the value to ensure proper system startup. This issue was identified on Lenovo P1 G8 during the Linux enablement program.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lenovo P1 G8
Linuxmint
Linux Kernel
Ubuntu