Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore esdhc_change_pinstate() checks for pins_100mhz and pins_200mhz at the top of the function and returns -EINVAL if either is not defined. This prevents the default case from ever being reached, which means devices with a sleep pinctrl state but without high-speed pin states (100mhz/ 200mhz) can never restore their default pin configuration. Move the IS_ERR checks for pins_100mhz and pins_200mhz into their respective switch cases.
References
- https://git.kernel.org/stable/c/5adc14cd4b905629d5b9163b3a416dcab24c7ce2
- https://git.kernel.org/stable/c/aa276aa6cbfbc5622bf974cf9be1d579ce4a5fab
- https://git.kernel.org/stable/c/bb72b2398c05fd0a4ebf13f49c7d599d7023d484
FAQ
What is CVE-2026-68465?
CVE-2026-68465 is a documented vulnerability. In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore esdhc_change_pinstate() checks for pins_100mhz an...
How severe is CVE-2026-68465?
CVSS scoring is not yet available for CVE-2026-68465. Check NVD for updates.
Is there a patch for CVE-2026-68465?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.