CVE-2026-72007
Last modified
CVE-2026-72007 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx: Fix i.MX8MP VC8000E power up sequence Per errata[1]: ERR050531: VPU_NOC power down handshake may hang during VC8000E/VPUMIX power up/down cycling. Description: VC8000E reset de-assertion edge and AXI clock may have a timing issue. Workaround: Set bit2 (vc8000e_clk_en) of BLK_CLK_EN_CSR to 0 to gate off both AXI clock and VC8000E clock sent to VC8000E and AXI clock sent to VPU_NOC m_v_2 interface during VC8000E power up(VC8000E reset is de-asserted by HW) Add a bool variable is_errata_err050531 in 'struct imx8m_blk_ctrl_domain_data' to represent whether the workaround is needed. If is_errata_err050531 is true, first clear the clk before powering up gpc, then enable the clk after powering up gpc. [1] https://www.nxp.com/webapp/Download?colCode=IMX8MP_1P33A. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx: Fix i.MX8MP VC8000E power up sequence Per errata[1]: ERR050531: VPU_NOC power down handshake may hang during VC8000E/VPUMIX power up/down cycling. Description: VC8000E reset de-assertion edge and AXI clock may have a timing issue. Workaround: Set bit2 (vc8000e_clk_en) of BLK_CLK_EN_CSR to 0 to gate off both AXI clock and VC8000E clock sent to VC8000E and AXI clock sent to VPU_NOC m_v_2 interface during VC8000E power up(VC8000E reset is de-asserted by HW) Add a bool variable is_errata_err050531 in 'struct imx8m_blk_ctrl_domain_data' to represent whether the workaround is needed. If is_errata_err050531 is true, first clear the clk before powering up gpc, then enable the clk after powering up gpc. [1] https://www.nxp.com/webapp/Download?colCode=IMX8MP_1P33A
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= a1a5f15f7f6cb5c291f072af843305638c935be6, < 87af3ebc112fb3f06753794390daf0f665f151b4; >= a1a5f15f7f6cb5c291f072af843305638c935be6, < c498928f85651b56a4041ea165a22037eae69580; >= a1a5f15f7f6cb5c291f072af843305638c935be6, < 4ff3960f3527189bc115a927ed3561c758f562f1; >= a1a5f15f7f6cb5c291f072af843305638c935be6, < 4907f4c2d98b97e640191af5bcf2814ee1034b76; >= a1a5f15f7f6cb5c291f072af843305638c935be6, < 25e252bcf1593b420b12a7231d9dd64b885a2ae2 |
| Linux | Linux | 6.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-72007?
How severe is CVE-2026-72007?
How do I fix CVE-2026-72007?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-71993MSI Radix AXE6600 router firmware version v781521 contains a…9.8
- CVE-2026-7200A flaw has been found in SourceCodester Pharmacy Sales and I…4.3
- CVE-2026-72003In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-72004In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72005In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72006In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72008In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72009In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-7201CWE-639: Authorization Bypass Through User-Controlled Key in…8.8
- CVE-2026-72010In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72011In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72012In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2026-72007?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
