CVE-2026-72009

Source
https://cve.org/CVERecord?id=CVE-2026-72009
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72009.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72009
Downstream
Published
2026-08-15T05:51:39Z
Modified
2026-08-18T03:56:17Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
pmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI
Details

In the Linux kernel, the following vulnerability has been resolved:

pmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI

The MIPI DSI and CSI domains share control bits for clock and reset, which can lead to incorrect behavior if one domain disables the shared resource while the other is still active.

To fix the issue, introduce a shared MIPI PHY power domain to own the common resources and make DSI and CSI its subdomains. This ensures the shared bits are properly managed and not disabled while still in use.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72009.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e9aa77d413c903ba4cf7da3fe0b419cae5b97a81
Fixed
4fd5b33faf092ef2d09f730a7d9e49f9e976ac67
Fixed
4ba6d7166750d0b810c6cfc0b1df7585f513b48c
Fixed
99611233f8cda833169fa6487d5dacdf189e5cb0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72009.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.1.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72009.json"