CVE-2026-68465
Last modified
CVE-2026-68465 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore esdhc_change_pinstate() checks for pins_100mhz and pins_200mhz at the top of the function and returns -EINVAL if either is not defined. This prevents the default case from ever being reached, which means devices with a sleep pinctrl state but without high-speed pin states (100mhz/ 200mhz) can never restore their default pin configuration. Move the IS_ERR checks for pins_100mhz and pins_200mhz into their respective switch cases.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore esdhc_change_pinstate() checks for pins_100mhz and pins_200mhz at the top of the function and returns -EINVAL if either is not defined. This prevents the default case from ever being reached, which means devices with a sleep pinctrl state but without high-speed pin states (100mhz/ 200mhz) can never restore their default pin configuration. Move the IS_ERR checks for pins_100mhz and pins_200mhz into their respective switch cases.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 676a83855614635af3bf31ad3f8fec4031f81354, < aa276aa6cbfbc5622bf974cf9be1d579ce4a5fab; >= 676a83855614635af3bf31ad3f8fec4031f81354, < bb72b2398c05fd0a4ebf13f49c7d599d7023d484; >= 676a83855614635af3bf31ad3f8fec4031f81354, < 5adc14cd4b905629d5b9163b3a416dcab24c7ce2 |
| Linux | Linux | 6.16 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-68465?
How severe is CVE-2026-68465?
How do I fix CVE-2026-68465?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6846A flaw was found in binutils. A heap-buffer-overflow vulnera…7.8
- CVE-2026-68460In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68461In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-68462In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-68463In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68464In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68466In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-68467In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-68468In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68469In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6847Remote Code Execution vulnerability exists in ThemisNETPanel…9.3
- CVE-2026-68470In the Linux kernel, the following vulnerability has been re…8.8
Are you affected by CVE-2026-68465?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
