Linux Kernel Power Management Domain Detach Procedure Improvement

Vulnerability

A vulnerability in the Linux kernel's power management domain handling for virtual devices has been addressed. When a device is attached to a power management (PM) domain, the kernel enables runtime PM for the virtual device. However, there was no mechanism to disable runtime PM when the device is detached from the PM domain. This oversight could lead to runtime PM remaining active for detached virtual devices, causing potential NULL pointer dereference errors and unnecessary performance state votes. The vulnerability affects the Linux kernel stable tree.

Impact

Failure to properly manage the power state of virtual devices could lead to runtime errors, such as NULL pointer dereferences, and unnecessary performance state votes, which could impact system performance.

Remediation

Users can upgrade to the latest version of the Linux kernel stable tree to address this vulnerability.

Added: Jun 8, 2026, 5:53 PM
Updated: Jun 8, 2026, 5:53 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
3.1
remediation
7.7
relevance
9.2
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.