LiveActive security incident?Get immediate response
CVE Record

CVE-2026-23187: pmdomain: imx8m-blk-ctrl: fix out-of-range access of bc->domains

In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx8m-blk-ctrl: fix out-of-range access of bc->domains Fix out-of-range access of bc->domains in imx8m_blk_ctrl_remove().

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2026-23187 is a Linux kernel bug in the imx8m-blk-ctrl power-domain removal path. The public record says it fixes an out-of-range access. Business impact is unclear because no CVSS score, CWE, crash impact, privilege requirement, or exploitation evidence is provided.

Executive priority

Treat this as a targeted kernel maintenance item, not an emergency, based on current evidence. Prioritize embedded or specialized Linux systems using the affected driver and rely on vendor kernel guidance for patch timing.

Technical view

The issue is an out-of-range access of bc->domains in imx8m_blk_ctrl_remove() within the Linux kernel pmdomain imx8m-blk-ctrl code. The source bundle identifies stable kernel commits as references, but does not describe exploitability, trigger conditions, or security impact beyond the bounds issue.

Likely exposure

Exposure appears limited to Linux kernels that include and use the imx8m-blk-ctrl pmdomain driver. The source metadata lists Linux as affected and includes kernel version entries, but does not clearly map distributions or device products.

Exploitation context

No active exploitation is supported by the provided sources. The CVE is not marked KEV, and the bundle provides no public exploit, attack path, privilege requirement, or remote/local trigger description.

Researcher notes

The public evidence is thin: only the resolved bug description, affected Linux metadata, and stable commit references are provided. Key unknowns include impact, reachability, attacker privileges, crashability, and exact fixed version mapping across downstream kernels.

Mitigation direction

  • Check Linux vendor or distribution advisories for CVE-2026-23187 applicability.
  • Update to a kernel release containing the referenced stable fixes when available.
  • Prioritize devices using the imx8m-blk-ctrl pmdomain driver.
  • Track fleet kernel versions against vendor-fixed packages or upstream stable commits.

Validation and detection

  • Inventory systems running Linux kernels with imx8m-blk-ctrl support enabled.
  • Compare deployed kernel builds against vendor advisories for CVE-2026-23187.
  • Confirm whether referenced stable commits are included in maintained kernel branches.
  • Document exclusions where the relevant driver is absent or unused.
Prepared
Confidence
medium
Sources
7

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2026-23187 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
0ADP providers
6Source links

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux2684ac05a8c4d2d5c49e6c11eb6206b30a284813, 2684ac05a8c4d2d5c49e6c11eb6206b30a284813, 2684ac05a8c4d2d5c49e6c11eb6206b30a284813, 2684ac05a8c4d2d5c49e6c11eb6206b30a284813, 2684ac05a8c4d2d5c49e6c11eb6206b30a284813unaffected
LinuxLinux5.16, 0, 6.1.163, 6.6.124, 6.12.70, 6.18.10, 6.19affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.