CVE-2026-23116

CWE-6677 documents7 sources
Severity
5.5MEDIUM
EPSS
0.0%
top 96.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14

Description

In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx8m-blk-ctrl: Remove separate rst and clk mask for 8mq vpu For i.MX8MQ platform, the ADB in the VPUMIX domain has no separate reset and clock enable bits, but is ungated and reset together with the VPUs. So we can't reset G1 or G2 separately, it may led to the system hang. Remove rst_mask and clk_mask of imx8mq_vpu_blk_ctl_domain_data. Let imx8mq_vpu_power_notifier() do really vpu reset.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

NVDlinux/linux_kernel5.186.1.162+4
CVEListV5linux/linux608d7c325e855cb4a853afef3cd9f0df594bd12d8859e336d233e61a4c40d40dc6a9f21e8b9b719c+5
Debianlinux< 6.1.162-1+2

Patches

🔴Vulnerability Details

3
CVEList
pmdomain: imx8m-blk-ctrl: Remove separate rst and clk mask for 8mq vpu2026-02-14
GHSA
GHSA-44pj-mggw-c3m7: In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx8m-blk-ctrl: Remove separate rst and clk mask for 8mq vpu For i2026-02-14
OSV
CVE-2026-23116: In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx8m-blk-ctrl: Remove separate rst and clk mask for 8mq vpu For i2026-02-14

📋Vendor Advisories

2
Red Hat
kernel: Kernel: Local denial of service via incorrect VPU power management on i.MX8MQ2026-02-14
Debian
CVE-2026-23116: linux - In the Linux kernel, the following vulnerability has been resolved: pmdomain: i...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-23116 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-23116 (MEDIUM CVSS 5.5) | In the Linux kernel | cvebase.io