Critical Alert 1 Active Exploit Detected Today

CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2026-90282NVD

Vulnerability Summary

In the Linux kernel, the following vulnerability has been resolved:

phy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early runtime suspend

There is a small window where the runtime suspend callback may run
after pm_runtime_enable() and before pm_runtime_forbid(). In this
case, a crash occurs because runtime suspend/resume dereferences
qmp->phy pointer, which is not yet initialized:
`if (!qmp->phy->init_count) {`

This can also happen if user re-enables runtime-pm via the sysfs
attribute before qmp phy is initialized.

Similarly to other qcom phy drivers, introduce a qmp->phy_initialized
variable that can be used to avoid relying on the possibly uninitialized
phy pointer.
Severity Level
UNKNOWN
Published Date
Sep 17, 2026
Last Modified
Sep 17, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.20%Probability
Root Weakness (CWE)
N/A

Affected & Patched Versions

Affected Versions
  • Linux Linux >= e464a3180a43b6596bd267f9f274e1793bfb8150 and < 602059c5128a78857ca92bd22791ab640185e381
  • Linux Linux >= e464a3180a43b6596bd267f9f274e1793bfb8150 and < 29449ce1f5958e36df80318878016e3ecac26b40
  • Linux Linux >= e464a3180a43b6596bd267f9f274e1793bfb8150 and < 52ad86ea5f98d29a7a29d9ba12e24276c6e30acd
  • Linux Linux >= e464a3180a43b6596bd267f9f274e1793bfb8150 and < 0f9789d1b63e7d9f868ac9c29564339a4c03ceb5
  • Linux Linux >= e464a3180a43b6596bd267f9f274e1793bfb8150 and < 8e3687f7e18fe84372e86875709d56c37e7525a8
  • Linux Linux >= 6.6
Patched Versions
  • Linux Linux 602059c5128a78857ca92bd22791ab640185e381
  • Linux Linux 29449ce1f5958e36df80318878016e3ecac26b40
  • Linux Linux 52ad86ea5f98d29a7a29d9ba12e24276c6e30acd
  • Linux Linux 0f9789d1b63e7d9f868ac9c29564339a4c03ceb5
  • Linux Linux 8e3687f7e18fe84372e86875709d56c37e7525a8
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.