CVE-2026-72007: pmdomain: imx: Fix i.MX8MP VC8000E power up sequence

Published Aug 15, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

pmdomain: imx: Fix i.MX8MP VC8000E power up sequence

Per errata[1]: ERR050531: VPUNOC power down handshake may hang during VC8000E/VPUMIX power up/down cycling. Description: VC8000E reset de-assertion edge and AXI clock may have a timing issue. Workaround: Set bit2 (vc8000eclken) of BLKCLKENCSR to 0 to gate off both AXI clock and VC8000E clock sent to VC8000E and AXI clock sent to VPUNOC mv2 interface during VC8000E power up(VC8000E reset is de-asserted by HW)

Add a bool variable iserrataerr050531 in 'struct imx8mblkctrldomaindata' to represent whether the workaround is needed. If iserrataerr050531 is true, first clear the clk before powering up gpc, then enable the clk after powering up gpc.

[1] https://www.nxp.com/webapp/Download?colCode=IMX8MP1P33A

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Apply the per errata[1] workaround by setting bit2 (vc8000e_clk_en) of BLK_CLK_EN_CSR to 0 to gate off both AXI clock and VC8000E clock being sent to VC8000E during the ERR050531-related power up/down sequence timing issue.

    Linux kernel pmdomain/imx (i.MX8MP VC8000E power up sequence) BLK_CLK_EN_CSR bit2 (vc8000e_clk_en) = 0
  2. Configuration

    Introduce/use the bool is_errata_err050531 to represent whether the workaround for ERR050531 is needed; when is_errata_err050531 is true, first clear the clk before proceeding with the affected VC8000E/AXI clock power sequence.

    Linux kernel pmdomain/imx (VC8000E ERR050531 workaround variable) is_errata_err050531 = true/false

Event History

Aug 15, 2026
CVE Published
via MITRE·05:51 AM
Data Sourced
via MITRE·05:51 AM
Description
Data Sourced
via NVD·06:20 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-72007?

CVE-2026-72007 has a risk rating of 14, indicating a significant impact on system stability.

2

How do I fix CVE-2026-72007?

To resolve CVE-2026-72007, update to the latest version of the Linux kernel that includes the patch addressing the power up sequence of the i.MX8MP VC8000E.

3

What systems are affected by CVE-2026-72007?

CVE-2026-72007 affects systems running the Linux kernel and utilizing the i.MX8MP VC8000E component.

4

What does CVE-2026-72007 affect in the i.MX8MP architecture?

CVE-2026-72007 pertains to the power up and down sequence of the VC8000E within the i.MX8MP architecture, which may lead to hangs during operation.

5

Is there a public disclosure for CVE-2026-72007?

Yes, CVE-2026-72007 was publicly disclosed with solutions provided in the Linux kernel updates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203