CVE-2026-90280 | Linux Kernel up to 6.6.156/6.12.109/6.18.51/7.2.5 Qmp Usb Runtime Suspend Callback phy uninitialized pointer
A vulnerability identified as problematic has been detected in Linux Kernel up to 6.6.156/6.12.109/6.18.51/7.2.5. Impacted is the function Runtime Suspend Callback of the component Qmp Usb. This manipulation of the argument phy causes uninitialized pointer.
This vulnerability is tracked as CVE-2026-90280. The attack is restricted to local execution. No exploit exists.
You should upgrade the affected component.