---
id: CVE-2026-23446
title: 'net: usb: aqc111: Do not perform PM inside suspend callback'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net: usb: aqc111: Do not perform PM inside suspend callback

  syzbot reports "task hung in rpm_resume"

  This is caused by aqc111_suspend calling
  the PM variant of its wr…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc <
    cc06ac99fd78839b2d38850785731ef131d9ae26
  - >-
    Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc <
    b87f361d41f9a7f1f6c426947ca815651c481376
  - >-
    Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc <
    621f2f43741b51f62d767eb4752fbcefe2526926
  - >-
    Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc <
    4de6a43e8ecf961feabddf0e9d6911081d2ed218
  - >-
    Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc <
    3267bcb744ee8a2feabaa7ab69473f086f67fd71
  - >-
    Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc <
    d3e32a612c6391ca9b7c183aeec22b4fd24c300c
  - >-
    Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc <
    98e8aed64614b0c199d5f0391fbe1a4331cb5773
  - >-
    Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc <
    069c8f5aebe4d5224cf62acc7d4b3486091c658a
  - Linux 5.0
published: '2026-04-03'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T08:46:14.104Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-23446'
references:
  - url: 'https://git.kernel.org/stable/c/cc06ac99fd78839b2d38850785731ef131d9ae26'
  - url: 'https://git.kernel.org/stable/c/b87f361d41f9a7f1f6c426947ca815651c481376'
  - url: 'https://git.kernel.org/stable/c/621f2f43741b51f62d767eb4752fbcefe2526926'
  - url: 'https://git.kernel.org/stable/c/4de6a43e8ecf961feabddf0e9d6911081d2ed218'
  - url: 'https://git.kernel.org/stable/c/3267bcb744ee8a2feabaa7ab69473f086f67fd71'
  - url: 'https://git.kernel.org/stable/c/d3e32a612c6391ca9b7c183aeec22b4fd24c300c'
  - url: 'https://git.kernel.org/stable/c/98e8aed64614b0c199d5f0391fbe1a4331cb5773'
  - url: 'https://git.kernel.org/stable/c/069c8f5aebe4d5224cf62acc7d4b3486091c658a'
tags:
  - cve.org
epss: 0.00129
epssPercentile: 0.02073
ingestedAt: '2026-09-08T15:33:26.992Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

net: usb: aqc111: Do not perform PM inside suspend callback

syzbot reports "task hung in rpm_resume"

This is caused by aqc111_suspend calling
the PM variant of its write_cmd routine.

The simplified call trace looks like this:

rpm_suspend()
  usb_suspend_both() - here udev->dev.power.runtime_status == RPM_SUSPENDING
    aqc111_suspend() - called for the usb device interface
      aqc111_write32_cmd()
        usb_autopm_get_interface()
          pm_runtime_resume_and_get()
            rpm_resume() - here we call rpm_resume() on our parent
              rpm_resume() - Here we wait for a status change that will never happen.

At this point we block another task which holds
rtnl_lock and locks up the whole networking stack.

Fix this by replacing the write_cmd calls with their _nopm variants

## Affected

- `Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc < cc06ac99fd78839b2d38850785731ef131d9ae26`
- `Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc < b87f361d41f9a7f1f6c426947ca815651c481376`
- `Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc < 621f2f43741b51f62d767eb4752fbcefe2526926`
- `Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc < 4de6a43e8ecf961feabddf0e9d6911081d2ed218`
- `Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc < 3267bcb744ee8a2feabaa7ab69473f086f67fd71`
- `Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc < d3e32a612c6391ca9b7c183aeec22b4fd24c300c`
- `Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc < 98e8aed64614b0c199d5f0391fbe1a4331cb5773`
- `Linux >= e58ba4544c7771591d1e3157bc01b4a8e4d1c3fc < 069c8f5aebe4d5224cf62acc7d4b3486091c658a`
- `Linux 5.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
