CVE-2026-23446None▾ SunlitIn the Linux kernel, the following vulnerability has been resolved: net: usb: aqc111: Do not perform PM inside suspend callback syzbot reports "task hung in rpm_resume" This is caused by aqc111_suspend calling the PM variant of its wr…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Last analysed / modified upstream
0.1%
In the Linux kernel, the following vulnerability has been resolved:
net: usb: aqc111: Do not perform PM inside suspend callback
syzbot reports "task hung in rpm_resume"
This is caused by aqc111_suspend calling the PM variant of its write_cmd routine.
The simplified call trace looks like this:
rpm_suspend() usb_suspend_both() - here udev->dev.power.runtime_status == RPM_SUSPENDING aqc111_suspend() - called for the usb device interface aqc111_write32_cmd() usb_autopm_get_interface() pm_runtime_resume_and_get() rpm_resume() - here we call rpm_resume() on our parent rpm_resume() - Here we wait for a status change that will never happen.
At this point we block another task which holds rtnl_lock and locks up the whole networking stack.
Fix this by replacing the write_cmd calls with their _nopm variants
Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc < cc06ac99fd78839b2d38850785731ef131d9ae26Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc < b87f361d41f9a7f1f6c426947ca815651c481376Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc < 621f2f43741b51f62d767eb4752fbcefe2526926Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc < 4de6a43e8ecf961feabddf0e9d6911081d2ed218Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc < 3267bcb744ee8a2feabaa7ab69473f086f67fd71Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc < d3e32a612c6391ca9b7c183aeec22b4fd24c300cLinux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc < 98e8aed64614b0c199d5f0391fbe1a4331cb5773Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc < 069c8f5aebe4d5224cf62acc7d4b3486091c658aLinux 5.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-68286NoneIn the Linux kernel, the following vulnerability has been resolved: drop_monitor: perform u64_stats updates under IRQ-disabled section In net_dm_packet_trace_kfree_skb_hit() and net_dm_hw_trap_packet_probe(), u64_stats_update_begin() /…
CVE-2026-68337NoneIn the Linux kernel, the following vulnerability has been resolved: bpf: Reject redirect helpers without a bpf_net_context The bpf_redirect*() helpers and skb_do_redirect() obtain the per-task bpf_redirect_info via bpf_net_ctx_get_ri()…
CVE-2026-68287High· 7.5In the Linux kernel, the following vulnerability has been resolved: drop_monitor: fix size calculations for 64-bit attributes net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() use nla_put_u64_64bit() to append 64-bit attri…
CVE-2026-68288NoneIn the Linux kernel, the following vulnerability has been resolved: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() open code the NET_DM_ATTR_PAYLOAD attribute to a…
CVE-2026-68289NoneIn the Linux kernel, the following vulnerability has been resolved: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() In tipc_recvmsg(), the copy length is computed as: copy = min_t(int, dlen - offset, buflen); buf…
CVE-2026-68303NoneIn the Linux kernel, the following vulnerability has been resolved: drm/vc4: hvs/v3d: Fix null dereference in unbind The hvs and v3d drivers use dev_get_drvdata(master) in their unbind functions