🛡️ CVE-2025-71193 on Debian — linux
Description
In the Linux kernel, the following vulnerability has been resolved: phy: qcom-qusb2: Fix NULL pointer dereference on early suspend Enabling runtime PM before attaching the QPHY instance as driver data can lead to a NULL pointer dereference in runtime PM callbacks that expect valid driver data. There is a small window where the suspend callback may run after PM runtime enabling and before runtime forbid. This causes a sporadic crash during boot: `` Unable to handle kernel NULL pointer dereference at virtual address 00000000000000a1 [...] CPU: 0 UID: 0 PID: 11 Comm: kworker/0:1 Not tainted 6.16.7+ #116 PREEMPT Workqueue: pm pm_runtime_work pstate: 20000005 (nzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : qusb2_phy_runtime_suspend+0x14/0x1e0 [phy_qcom_qusb2] lr : pm_generic_runtime_suspend+0x2c/0x44 [...] `` Attach the QPHY instance as driver data before enabling runtime PM to prevent NULL pointer dereference in runtime PM callbacks. Reorder pm_runtime_enable() and pm_runtime_forbid() to prevent a short window where an unnecessary runtime suspend can occur. Use the devres-managed version to ensure PM runtime is symmetrically disabled during driver removal for proper cleanup.
Distribution advisory
This page covers CVE-2025-71193 as tracked by Debian, for the package linux. The fix is available in version 6.18.8-1; earlier versions remain affected.
Affected software
DEBIAN-CVE-2025-71193 is recorded against 1 package.
- linux (fixed in 6.18.8-1)
Timeline and source
Published on 4 February 2026 and last revised on 4 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
CVE-2025-71193 on other distributions
Each distribution ships its own build and its own fixed version. Pick the one you run:
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| linux | — | 6.18.8-1 |
References
Similar Threats
- Unknown CGA-23jx-hhcx-m389
- Unknown CGA-2qp7-6757-fmgc
- Unknown CGA-2rj5-jc55-r267
- Unknown CGA-3m96-cwq8-6xmx
- Unknown CGA-3qj9-973w-fh9g
More DEBIAN CVE 2025 advisories
Browse all of DEBIAN CVE 2025 in the advisory index.
- DEBIAN-CVE-2025-71185
- DEBIAN-CVE-2025-71186
- DEBIAN-CVE-2025-71187
- DEBIAN-CVE-2025-71188
- DEBIAN-CVE-2025-71189
- DEBIAN-CVE-2025-71190
- DEBIAN-CVE-2025-71191
- DEBIAN-CVE-2025-71192
- DEBIAN-CVE-2025-71194
- DEBIAN-CVE-2025-71195
- DEBIAN-CVE-2025-71196
- DEBIAN-CVE-2025-71197
- DEBIAN-CVE-2025-71198
- DEBIAN-CVE-2025-71199
- DEBIAN-CVE-2025-71200
- DEBIAN-CVE-2025-71201
Free Vulnerability Check
Is your site affected by DEBIAN-CVE-2025-71193?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against DEBIAN-CVE-2025-71193 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.