5.5

CVE-2025-22011

ARM: dts: bcm2711: Fix xHCI power-domain

In the Linux kernel, the following vulnerability has been resolved:

ARM: dts: bcm2711: Fix xHCI power-domain

During s2idle tests on the Raspberry CM4 the VPU firmware always crashes
on xHCI power-domain resume:

root@raspberrypi:/sys/power# echo freeze > state
[   70.724347] xhci_suspend finished
[   70.727730] xhci_plat_suspend finished
[   70.755624] bcm2835-power bcm2835-power: Power grafx off
[   70.761127]  USB: Set power to 0

[   74.653040]  USB: Failed to set power to 1 (-110)

This seems to be caused because of the mixed usage of
raspberrypi-power and bcm2835-power at the same time. So avoid
the usage of the VPU firmware power-domain driver, which
prevents the VPU crash.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 6.8 < 6.12.21
Linux ≫ Linux Kernel Version >= 6.13 < 6.13.9
Linux ≫ Linux Kernel Version 6.14 Update rc1
Linux ≫ Linux Kernel Version 6.14 Update rc2
Linux ≫ Linux Kernel Version 6.14 Update rc3
Linux ≫ Linux Kernel Version 6.14 Update rc4
Linux ≫ Linux Kernel Version 6.14 Update rc5
Linux ≫ Linux Kernel Version 6.14 Update rc6
Linux ≫ Linux Kernel Version 6.14 Update rc7
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.084
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA-ADP 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/b8a47aa0b3df701d0fc41b3caf78d00571776be0
Patch
https://git.kernel.org/stable/c/393947e06867923d4c2be380d46efd03407a8ce2
Patch
https://git.kernel.org/stable/c/f44fa354a0715577ca32b085f6f60bcf32c748dd
Patch