CVE-2026-68219
In the Linux kernel, the following vulnerability has been resolved: media: nxp: imx8-isi: Fix potential out-of-bounds issues The maximum downscaling factor supported by ISI can be up to 16.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.18%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: media: nxp: imx8-isi: Fix potential out-of-bounds issues The maximum downscaling factor supported by ISI can be up to 16. Add minimum value constraint before applying the setting to hardware. Otherwise, the process will not respond even when Ctrl+C is executed.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.18% probability · 7th percentile
- CISA KEV
- Not listed
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/28ae75dba701d7aa69a36802c398582933d3e0e6
- https://git.kernel.org/stable/c/57a7ec5c9f38ce6c4d6209c4b75c8e57e1fea6cf
- https://git.kernel.org/stable/c/690cdda752f3dc6b7a8b2d4a243e0207b66a1f37
- https://git.kernel.org/stable/c/75cdfaa7c908ca06d564170da9c80fb579f149a5
- https://git.kernel.org/stable/c/ba7e1b06cbdad3b7c3314390cca22aff42f655d4
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.