CVE-2025-71108

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: Handle incorrect num_connectors capability The UCSI spec states that the num_connectors field is 7 bits, and the 8th bit is reserved and should be set to zero. Some buggy FW has been known to set this bit, and it can lead to a system not booting. Flag that the FW is not behaving correctly, and auto-fix the value so that the system boots correctly. Found on Lenovo P1 G8 during Linux enablement program. The FW will be fixed, but seemed worth addressing in case it hit platforms that aren't officially Linux supported.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:4.13:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc7:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc8:*:*:*:*:*:*

History

17 Jun 2026, 10:03

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: usb: typec: ucsi: Manejar capacidad incorrecta de num_connectors La especificación UCSI establece que el campo num_connectors es de 7 bits, y el octavo bit está reservado y debe establecerse a cero. Se sabe que algunos FW defectuosos han establecido este bit, y esto puede llevar a que un sistema no arranque. Indicar que el FW no se está comportando correctamente y corregir automáticamente el valor para que el sistema arranque correctamente. Encontrado en Lenovo P1 G8 durante el programa de habilitación de Linux. El FW se corregirá, pero pareció valer la pena abordarlo en caso de que afectara a plataformas que no son oficialmente compatibles con Linux.

25 Mar 2026, 19:32

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://git.kernel.org/stable/c/07c8d2a109d847775b3b4e2c3294c8e1eea75432 - () https://git.kernel.org/stable/c/07c8d2a109d847775b3b4e2c3294c8e1eea75432 - Patch
References () https://git.kernel.org/stable/c/132fe187e0d940f388f839fe2cde9b84106ad20d - () https://git.kernel.org/stable/c/132fe187e0d940f388f839fe2cde9b84106ad20d - Patch
References () https://git.kernel.org/stable/c/3042a57a8e8bce4a3100c3f6f03dc372aab24943 - () https://git.kernel.org/stable/c/3042a57a8e8bce4a3100c3f6f03dc372aab24943 - Patch
References () https://git.kernel.org/stable/c/30cd2cb1abf4c4acdb1ddb468c946f68939819fb - () https://git.kernel.org/stable/c/30cd2cb1abf4c4acdb1ddb468c946f68939819fb - Patch
References () https://git.kernel.org/stable/c/58941bbb0050e365a98c64f1fc4a9a0ac127dba6 - () https://git.kernel.org/stable/c/58941bbb0050e365a98c64f1fc4a9a0ac127dba6 - Patch
References () https://git.kernel.org/stable/c/914605b0de8128434eafc9582445306830748b93 - () https://git.kernel.org/stable/c/914605b0de8128434eafc9582445306830748b93 - Patch
References () https://git.kernel.org/stable/c/f72f97d0aee4a993a35f2496bca5efd24827235d - () https://git.kernel.org/stable/c/f72f97d0aee4a993a35f2496bca5efd24827235d - Patch
First Time Linux
Linux linux Kernel
CPE cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc8:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:4.13:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc7:*:*:*:*:*:*

19 Jan 2026, 13:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/07c8d2a109d847775b3b4e2c3294c8e1eea75432 -
  • () https://git.kernel.org/stable/c/58941bbb0050e365a98c64f1fc4a9a0ac127dba6 -

14 Jan 2026, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-14 15:15

Updated : 2026-06-17 10:03


NVD link : CVE-2025-71108

Mitre link : CVE-2025-71108

CVE.ORG link : CVE-2025-71108


JSON object : View

Products Affected

linux

  • linux_kernel