In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI The MIPI DSI… (CVE-2026-72009)
A vulnerability in the Linux kernel related to the MIPI DSI and CSI domains sharing control bits for clock and reset has been resolved. The issue could cause incorrect behavior if one domain disables a shared resource while the other remains active. The fix introduces a shared MIPI PHY power domain to properly manage these shared resources and prevent premature disabling.
AI Analysis
Technical Summary
The vulnerability in the Linux kernel involves the MIPI DSI and CSI domains sharing control bits for clock and reset signals. Because these domains share resources, disabling the shared resource in one domain while the other is still active could lead to incorrect behavior. The resolution was to create a shared MIPI PHY power domain that owns the common resources, with DSI and CSI as its subdomains, ensuring proper management of the shared bits and preventing them from being disabled while still in use.
Potential Impact
If exploited, the vulnerability could cause incorrect behavior in the handling of shared clock and reset resources between the MIPI DSI and CSI domains. This could potentially affect the stability or functionality of devices relying on these subsystems. However, no specific exploit or active attacks are known.
Mitigation Recommendations
The vulnerability has been resolved in the Linux kernel by introducing a shared MIPI PHY power domain. Users and administrators should apply the official Linux kernel updates that include this fix. Patch status is not explicitly confirmed in the provided data; therefore, check the vendor or Linux kernel advisory for the current remediation guidance.
In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI The MIPI DSI… (CVE-2026-72009)
Description
A vulnerability in the Linux kernel related to the MIPI DSI and CSI domains sharing control bits for clock and reset has been resolved. The issue could cause incorrect behavior if one domain disables a shared resource while the other remains active. The fix introduces a shared MIPI PHY power domain to properly manage these shared resources and prevent premature disabling.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in the Linux kernel involves the MIPI DSI and CSI domains sharing control bits for clock and reset signals. Because these domains share resources, disabling the shared resource in one domain while the other is still active could lead to incorrect behavior. The resolution was to create a shared MIPI PHY power domain that owns the common resources, with DSI and CSI as its subdomains, ensuring proper management of the shared bits and preventing them from being disabled while still in use.
Potential Impact
If exploited, the vulnerability could cause incorrect behavior in the handling of shared clock and reset resources between the MIPI DSI and CSI domains. This could potentially affect the stability or functionality of devices relying on these subsystems. However, no specific exploit or active attacks are known.
Mitigation Recommendations
The vulnerability has been resolved in the Linux kernel by introducing a shared MIPI PHY power domain. Users and administrators should apply the official Linux kernel updates that include this fix. Patch status is not explicitly confirmed in the provided data; therefore, check the vendor or Linux kernel advisory for the current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-7wvh-6fjm-x43j
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-72009"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a808b79bf8831d53950249e
Added to database: 08/15/2026, 15:53:29 UTC
Last enriched: 08/15/2026, 17:09:56 UTC
Last updated: 08/15/2026, 18:01:17 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.