CVE-2026-23446Patch(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: net: usb: aqc111: Do not perform PM inside suspend callback syzbot reports "task hung in rpm_resume" This is caused by aqc111_suspend calling the PM variant of its write_cmd routine. The simplified call trace looks like this: rpm_suspend() usb_suspend_both() - here udev->dev.power.runtime_status == RPM_SUSPENDING aqc111_suspend() - called for the usb device interface aqc111_write32_cmd() usb_autopm_get_interface() pm_runtime_resume_and_get() rpm_resume() - here we call rpm_resume() on our parent rpm_resume() - Here we wait for a status change that will never happen. At this point we block another task which holds rtnl_lock and locks up the whole networking stack. Fix this by replacing the write_cmd calls with their _nopm variants

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-04-03); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-03: 1Mentions · 2026-04-25: 1Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-25: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-25: 104-0304-25
Signal classification1 categories
Patch
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • WindowsForum@windowsforum
    Patch

    🪟 CVE-2026-23446: even Linux USB Ethernet can faceplant in suspend—because power management loves drama. Fix is “use _nopm,” aka stop poking devices mid-transition. https://windowsforum.com/threads/cve-2026-23446-aqc111-usb-ethernet-suspend-deadlock-and-linux-fix.415092/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #PowerManagement #LinuxKernel #UsbEthernet #Cve202623446 https://t.co/3qrpsI0jW5

    Post summary

    The post announces CVE‑2026‑23446, a Linux USB Ethernet suspension deadlock, and provides a specific workaround of using "_nopm" while linking to a forum thread for further details.

    0000053
    1.1K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23446 In the Linux kernel, the following vulnerability has been resolved: net: usb: aqc111: Do not perform PM inside suspend callback syzbot reports "task hung in rpm_res… https://www.cve.org/CVERecord?id=CVE-2026-23446

    Post summary

    CVE-2026-23446 refers to a Linux kernel USB driver issue that has been fixed; the vulnerability has been resolved without any indication of active exploitation or PoC.

    0000098
    56.9K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel5.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more