CVE-2026-23187: pmdomain: imx8m-blk-ctrl: fix out-of-range access of bc->domains
In the Linux kernel, the following vulnerability has been resolved:
pmdomain: imx8m-blk-ctrl: fix out-of-range access of bc->domains
Fix out-of-range access of bc->domains in imx8m_blk_ctrl_remove().
Security readout for executives and security teams
Plain-English summary
CVE-2026-23187 is a Linux kernel bug in the imx8m-blk-ctrl power-domain removal path. The public record says it fixes an out-of-range access. Business impact is unclear because no CVSS score, CWE, crash impact, privilege requirement, or exploitation evidence is provided.
Executive priority
Treat this as a targeted kernel maintenance item, not an emergency, based on current evidence. Prioritize embedded or specialized Linux systems using the affected driver and rely on vendor kernel guidance for patch timing.
Technical view
The issue is an out-of-range access of bc->domains in imx8m_blk_ctrl_remove() within the Linux kernel pmdomain imx8m-blk-ctrl code. The source bundle identifies stable kernel commits as references, but does not describe exploitability, trigger conditions, or security impact beyond the bounds issue.
Likely exposure
Exposure appears limited to Linux kernels that include and use the imx8m-blk-ctrl pmdomain driver. The source metadata lists Linux as affected and includes kernel version entries, but does not clearly map distributions or device products.
Exploitation context
No active exploitation is supported by the provided sources. The CVE is not marked KEV, and the bundle provides no public exploit, attack path, privilege requirement, or remote/local trigger description.
Researcher notes
The public evidence is thin: only the resolved bug description, affected Linux metadata, and stable commit references are provided. Key unknowns include impact, reachability, attacker privileges, crashability, and exact fixed version mapping across downstream kernels.
Mitigation direction
Check Linux vendor or distribution advisories for CVE-2026-23187 applicability.
Update to a kernel release containing the referenced stable fixes when available.
Prioritize devices using the imx8m-blk-ctrl pmdomain driver.
Track fleet kernel versions against vendor-fixed packages or upstream stable commits.
Validation and detection
Inventory systems running Linux kernels with imx8m-blk-ctrl support enabled.
Compare deployed kernel builds against vendor advisories for CVE-2026-23187.
Confirm whether referenced stable commits are included in maintained kernel branches.
Document exclusions where the relevant driver is absent or unused.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2026-23187 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
0CVSS vectors
3Timeline events
0ADP providers
6Source links
Vulnerability timeline
Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.
CVE reservedCVE Program
The CVE ID was reserved by the assigning CNA.
CVE publishedCVE Program
The CVE record was published.
Feb 14, 2026, 16:27 UTC (UTC+00:00)
CVE updatedCVE Program
The CVE record metadata indicates this as the latest update time.