Answer in brief
CVE-2026-90280 records a Unknown severity vulnerability in phy: qcom: qmp-usb: Fix possible NULL-deref on early runtime suspend. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=e464a3180a43b6596bd267f9f274e1793bfb8150 <9b28287c5dea7650e6dd317591b9e82b6e145365 || >=e464a3180a43b6596bd267f9f274e1793bfb8150 <f4e39ab1b2009a89c60e4cb9dbefb8140d405eff || >=e464a3180a43b6596bd267f9f274e1793bfb8150 <5547fd950d6bf72de861b6934341e7bb0888640c || >=e464a3180a43b6596bd267f9f274e1793bfb8150 <03455404fb6cbfd65842695df26739853fc1516b || >=e464a3180a43b6596bd267f9f274e1793bfb8150 <142c5593379273264474f31d5956b1a0065cd576 | 9b28287c5dea7650e6dd317591b9e82b6e145365, f4e39ab1b2009a89c60e4cb9dbefb8140d405eff, 5547fd950d6bf72de861b6934341e7bb0888640c, 03455404fb6cbfd65842695df26739853fc1516b, 142c5593379273264474f31d5956b1a0065cd576 |
| Linux/Linuxgeneric | 6.6 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usb: Fix possible NULL-deref on early runtime suspend There is a small window where the runtime suspend callback may run after pm_runtime_enable() and before pm_runtime_forbid(). In this case, a crash occurs because runtime suspend/resume dereferences qmp->phy pointer, which is not yet initialized: `if (!qmp->phy->init_count) {` This can also happen if user re-enables runtime-pm via the sysfs attribute before qmp phy is initialized. Similarly to other qcom phy drivers, introduce a qmp->phy_initialized variable that can be used to avoid relying on the possibly uninitialized phy pointer.
Quoted source text, attributed separately from HOL analysis.