SB2026040687 - Improper locking in Linux kernel net usb driver
Published: April 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2026-23446)
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to improper control of interaction with the power management subsystem in aqc111_suspend when handling a suspend callback. A local attacker can trigger a suspend operation to cause a denial of service.
The issue can lead to a hung task in rpm_resume and block another task holding rtnl_lock, which can lock up the networking stack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/069c8f5aebe4d5224cf62acc7d4b3486091c658a
- https://git.kernel.org/stable/c/3267bcb744ee8a2feabaa7ab69473f086f67fd71
- https://git.kernel.org/stable/c/4de6a43e8ecf961feabddf0e9d6911081d2ed218
- https://git.kernel.org/stable/c/621f2f43741b51f62d767eb4752fbcefe2526926
- https://git.kernel.org/stable/c/98e8aed64614b0c199d5f0391fbe1a4331cb5773
- https://git.kernel.org/stable/c/d3e32a612c6391ca9b7c183aeec22b4fd24c300c