A vulnerability was found in Linux Foundation Core ROM up to 2.1.1 and classified as problematic. The affected element is the function UpdateResetFlow::run of the component Subsystem Mode. Executing a manipulation can lead to time-of-check time-of-use.

This vulnerability is tracked as CVE-2026-11835. The attack is restricted to local execution. No exploit exists.

It is suggested to upgrade the affected component.