CVE-2025-71108
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/01/2026
Last modified:
14/01/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
usb: typec: ucsi: Handle incorrect num_connectors capability<br />
<br />
The UCSI spec states that the num_connectors field is 7 bits, and the<br />
8th bit is reserved and should be set to zero.<br />
Some buggy FW has been known to set this bit, and it can lead to a<br />
system not booting.<br />
Flag that the FW is not behaving correctly, and auto-fix the value<br />
so that the system boots correctly.<br />
<br />
Found on Lenovo P1 G8 during Linux enablement program. The FW will<br />
be fixed, but seemed worth addressing in case it hit platforms that<br />
aren&#39;t officially Linux supported.
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/132fe187e0d940f388f839fe2cde9b84106ad20d
- https://git.kernel.org/stable/c/3042a57a8e8bce4a3100c3f6f03dc372aab24943
- https://git.kernel.org/stable/c/30cd2cb1abf4c4acdb1ddb468c946f68939819fb
- https://git.kernel.org/stable/c/914605b0de8128434eafc9582445306830748b93
- https://git.kernel.org/stable/c/f72f97d0aee4a993a35f2496bca5efd24827235d



