{"api_version":"1","generated_at":"2026-09-25T11:01:09+00:00","cve":"CVE-2026-97512","urls":{"html":"https://cve.report/CVE-2026-97512","api":"https://cve.report/api/cve/CVE-2026-97512.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-97512","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-97512"},"summary":{"title":"spi: spi-qcom-qspi: Fix incomplete error handling in runtime PM","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: spi-qcom-qspi: Fix incomplete error handling in runtime PM\n\nThe runtime PM functions had incomplete error handling that could leave the\nsystem in an inconsistent state. If any operation failed midway through\nsuspend or resume, some resources would be left in the wrong state while\nothers were already changed, leading to potential clock/power imbalances.\n\nReorder the suspend/resume sequences to avoid brownout risk by ensuring the\nperformance state is set appropriately before clocks are enabled and clocks\nare disabled before dropping the performance state.\n\nFix by adding proper error checking for all operations and using goto-based\ncleanup to ensure all successfully acquired resources are properly released\non any error.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-24 17:17:29","updated_at":"2026-09-24 17:17:29"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/bb18a346271f87889bd64a3861c9a656a3509ea6","name":"https://git.kernel.org/stable/c/bb18a346271f87889bd64a3861c9a656a3509ea6","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/62dd3b8d3a92eb4e080b2ae491c2a5341654c1ee","name":"https://git.kernel.org/stable/c/62dd3b8d3a92eb4e080b2ae491c2a5341654c1ee","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/d283d5d4d9f6d081ddb65e371be26fffeb611c42","name":"https://git.kernel.org/stable/c/d283d5d4d9f6d081ddb65e371be26fffeb611c42","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-97512","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97512","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 62dd3b8d3a92eb4e080b2ae491c2a5341654c1ee git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 bb18a346271f87889bd64a3861c9a656a3509ea6 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 d283d5d4d9f6d081ddb65e371be26fffeb611c42 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.12.111 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.18.53 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.111 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.53 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/spi/spi-qcom-qspi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"62dd3b8d3a92eb4e080b2ae491c2a5341654c1ee","status":"affected","version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","versionType":"git"},{"lessThan":"bb18a346271f87889bd64a3861c9a656a3509ea6","status":"affected","version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","versionType":"git"},{"lessThan":"d283d5d4d9f6d081ddb65e371be26fffeb611c42","status":"affected","version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","versionType":"git"},{"lessThan":"6.12.111","status":"affected","version":"0","versionType":"semver"},{"lessThan":"6.18.53","status":"affected","version":"0","versionType":"semver"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/spi/spi-qcom-qspi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.111","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.53","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.111","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.53","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: spi-qcom-qspi: Fix incomplete error handling in runtime PM\n\nThe runtime PM functions had incomplete error handling that could leave the\nsystem in an inconsistent state. If any operation failed midway through\nsuspend or resume, some resources would be left in the wrong state while\nothers were already changed, leading to potential clock/power imbalances.\n\nReorder the suspend/resume sequences to avoid brownout risk by ensuring the\nperformance state is set appropriately before clocks are enabled and clocks\nare disabled before dropping the performance state.\n\nFix by adding proper error checking for all operations and using goto-based\ncleanup to ensure all successfully acquired resources are properly released\non any error."}],"providerMetadata":{"dateUpdated":"2026-09-24T16:05:09.279Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/62dd3b8d3a92eb4e080b2ae491c2a5341654c1ee"},{"url":"https://git.kernel.org/stable/c/bb18a346271f87889bd64a3861c9a656a3509ea6"},{"url":"https://git.kernel.org/stable/c/d283d5d4d9f6d081ddb65e371be26fffeb611c42"}],"title":"spi: spi-qcom-qspi: Fix incomplete error handling in runtime PM","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-97512","datePublished":"2026-09-24T16:05:09.279Z","dateReserved":"2026-09-24T16:01:01.151Z","dateUpdated":"2026-09-24T16:05:09.279Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-24 17:17:29","lastModifiedDate":"2026-09-24 17:17:29","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"97512","Ordinal":"1","Title":"spi: spi-qcom-qspi: Fix incomplete error handling in runtime PM","CVE":"CVE-2026-97512","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"97512","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: spi-qcom-qspi: Fix incomplete error handling in runtime PM\n\nThe runtime PM functions had incomplete error handling that could leave the\nsystem in an inconsistent state. If any operation failed midway through\nsuspend or resume, some resources would be left in the wrong state while\nothers were already changed, leading to potential clock/power imbalances.\n\nReorder the suspend/resume sequences to avoid brownout risk by ensuring the\nperformance state is set appropriately before clocks are enabled and clocks\nare disabled before dropping the performance state.\n\nFix by adding proper error checking for all operations and using goto-based\ncleanup to ensure all successfully acquired resources are properly released\non any error.","Type":"Description","Title":"spi: spi-qcom-qspi: Fix incomplete error handling in runtime PM"}]}}}