CVE-2026-68280

Source
https://cve.org/CVERecord?id=CVE-2026-68280
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68280.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68280
Downstream
Published
2026-08-10T12:02:11.434Z
Modified
2026-08-12T04:18:47.355104975Z
Summary
drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/bridge: cdns-dsi: Replace deprecated UNIVERSALDEVPM_OPS()

The deprecated UNIVERSALDEVPM_OPS() macro uses the provided callbacks for both runtime PM and system sleep. This causes the DSI clocks to be disabled twice: once during runtime suspend and again during system suspend, resulting in a WARN message from the clock framework when attempting to disable already-disabled clocks.

[ 84.384540] clk:231:5 already disabled [ 84.388314] WARNING: CPU: 2 PID: 531 at /drivers/clk/clk.c:1181 clkcoredisable+0xa4/0xac ... [ 84.579183] Call trace: [ 84.581624] clkcoredisable+0xa4/0xac [ 84.585457] clkdisable+0x30/0x4c [ 84.588857] cdnsdsisuspend+0x20/0x58 [cdnsdsi] [ 84.593651] pmgenericsuspend+0x2c/0x44 [ 84.597661] tiscipdsuspend+0xbc/0x15c [ 84.601670] dpmrun_callback+0x8c/0x14c [ 84.605588] __devicesuspend+0x1a0/0x56c [ 84.609594] dpmsuspend+0x17c/0x21c [ 84.613165] dpmsuspendstart+0xa0/0xa8 [ 84.617083] suspenddevicesandenter+0x12c/0x634 [ 84.621872] pmsuspend+0x1fc/0x368

To address this issue, replace UNIVERSALDEVPMOPS() with RUNTIMEPM_OPS(). Bridge and panel drivers should only deal with runtime PM, as the DRM framework manages system-wide power transitions through the bridge enable() and disable() hooks.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68280.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e19233955d9e9a9ae202723b9a38ef38e755b5c0
Fixed
c18d46d9830c29677be5213a067daafe1ac80e43
Fixed
347bc3a6a4d968c403d2292e5ad986294d919dfc
Fixed
c0384d6872f4dc2701960048a0be1a12a8d2dc6e
Fixed
1f9c6b74e79639179e90ad0c0fbeae26e31e044b
Fixed
2d8b08844c0ecc6f2002fa68711e779aa18c8585

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68280.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.18.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68280.json"