Files
CVEs-PoC/2025/CVE-2025-22011.md
2025-09-29 21:09:30 +02:00

1.3 KiB

CVE-2025-22011

Description

In the Linux kernel, the following vulnerability has been resolved:ARM: dts: bcm2711: Fix xHCI power-domainDuring s2idle tests on the Raspberry CM4 the VPU firmware always crasheson xHCI power-domain resume:root@raspberrypi:/sys/power# echo freeze > state[ 70.724347] xhci_suspend finished[ 70.727730] xhci_plat_suspend finished[ 70.755624] bcm2835-power bcm2835-power: Power grafx off[ 70.761127] USB: Set power to 0[ 74.653040] USB: Failed to set power to 1 (-110)This seems to be caused because of the mixed usage ofraspberrypi-power and bcm2835-power at the same time. So avoidthe usage of the VPU firmware power-domain driver, whichprevents the VPU crash.

POC

Reference

No PoCs from references.

Github