CVE-2026-68464

Source
https://cve.org/CVERecord?id=CVE-2026-68464
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68464.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68464
Downstream
Published
2026-08-15T05:51:23Z
Modified
2026-08-18T03:31:25Z
Summary
mmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled interrupt
Details

In the Linux kernel, the following vulnerability has been resolved:

mmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled interrupt

When using WIFI out-of-band wakeup, an "irq xxx: nobody cared" warning occurs. This happens because the usdhc interrupt is not disabled during system suspend when device_may_wakeup() returns false.

The sequence of events leading to this issue:

  1. System enters suspend without disabling usdhc interrupt (because device_may_wakeup() returns false for usdhc device)
  2. WIFI out-of-band wakeup triggers system resume via GPIO interrupt
  3. WIFI sends a Card interrupt before usdhc has fully resumed
  4. usdhc is still in runtime suspend state and cannot handle the interrupt properly
  5. The unhandled interrupt triggers "nobody cared" warning

Fix this by unconditionally disabling the usdhc interrupt during suspend and re-enabling it during resume, regardless of the wakeup capability. This ensures no interrupts are processed during the suspend/resume transition.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68464.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
676a83855614635af3bf31ad3f8fec4031f81354
Fixed
4f96903e2fd228aa96013372402d650f6dbe5cb3
Fixed
9bf4ee05a1109d889de9151ee78bd80293923f70
Fixed
9d87eaf985cef9581b6ed99b461b38e8cd666480

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68464.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.16.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68464.json"