Answer in brief
CVE-2026-97512 records a Unknown severity vulnerability in spi: spi-qcom-qspi: Fix incomplete error handling in runtime PM. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <62dd3b8d3a92eb4e080b2ae491c2a5341654c1ee || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <bb18a346271f87889bd64a3861c9a656a3509ea6 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <d283d5d4d9f6d081ddb65e371be26fffeb611c42 || >=0 <6.12.111 || >=0 <6.18.53 | 62dd3b8d3a92eb4e080b2ae491c2a5341654c1ee, bb18a346271f87889bd64a3861c9a656a3509ea6, d283d5d4d9f6d081ddb65e371be26fffeb611c42, 6.12.111, 6.18.53 |
Published upstream
Sep 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: spi: spi-qcom-qspi: Fix incomplete error handling in runtime PM The runtime PM functions had incomplete error handling that could leave the system in an inconsistent state. If any operation failed midway through suspend or resume, some resources would be left in the wrong state while others were already changed, leading to potential clock/power imbalances. Reorder the suspend/resume sequences to avoid brownout risk by ensuring the performance state is set appropriately before clocks are enabled and clocks are disabled before dropping the performance state. Fix by adding proper error checking for all operations and using goto-based cleanup to ensure all successfully acquired resources are properly released on any error.
Quoted source text, attributed separately from HOL analysis.