SB20260812253 - Improper resource shutdown or release in Linux kernel bridge cadence driver
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2026-68280)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown in cdns_dsi power management operations when handling runtime suspend and system suspend transitions. A local user can trigger suspend operations to cause a denial of service.
The issue results in a kernel warning when clocks are disabled twice.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1f9c6b74e79639179e90ad0c0fbeae26e31e044b
- https://git.kernel.org/stable/c/2d8b08844c0ecc6f2002fa68711e779aa18c8585
- https://git.kernel.org/stable/c/347bc3a6a4d968c403d2292e5ad986294d919dfc
- https://git.kernel.org/stable/c/c0384d6872f4dc2701960048a0be1a12a8d2dc6e
- https://git.kernel.org/stable/c/c18d46d9830c29677be5213a067daafe1ac80e43