PT-2026-64499 · Linux+2 · Linux Kernel+2

CVE-2026-64278

·

Published

2026-07-25

·

Updated

2026-09-07

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description On some i.MX platforms, certain I2C client drivers utilize a periodic workqueue that continues to trigger I2C transfers during system suspend and resume cycles. A critical time window exists between suspend noirq and the system entering suspend, as well as between the system starting to resume and resume noirq. During these intervals, I2C controller resources, including clock and pinctrl, may be disabled or not yet restored. If a workqueue triggers an I2C transfer during this period, the driver attempts to access I2C registers while hardware resources are unavailable, which can result in a system hang.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64278
OPENSUSE-SU-2026:11476-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu
I.Mx