PT-2026-5993 · Linux+1 · Linux Kernel+1

Published

2025-01-01

·

Updated

2026-05-20

·

CVE-2025-71193

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.16.7+ #116
Description The Linux kernel contains a flaw related to power management in the Qualcomm USB2 PHY driver (qcom-qusb2). Enabling runtime power management before the QPHY instance is attached as driver data can lead to a NULL pointer dereference within runtime power management callbacks. This can result in a sporadic crash during the boot process. The issue occurs due to a small window where the suspend callback may execute after runtime PM is enabled but before it is forbidden. The function qusb2 phy runtime suspend is involved in this issue.
Recommendations Versions prior to 6.16.7+ #116 should be updated to a newer version that includes the fix. Attach the QPHY instance as driver data before enabling runtime PM. Reorder the calls to pm runtime enable() and pm runtime forbid() to prevent unnecessary runtime suspend. Utilize the devres-managed version to ensure PM runtime is symmetrically disabled during driver removal.

Exploit

Related Identifiers

CVE-2025-71193
ECHO-C402-8176-3352
OPENSUSE-SU-2026:20416-1
SUSE-SU-2026:20838-1
SUSE-SU-2026:20931-1
SUSE-SU-2026:21284-1
USN-8278-1
USN-8289-1

Affected Products

Linux Kernel
Qualcomm Usb2 Phy