SB20260812327 - Improper input validation in Linux kernel nxp imx8-isi driver
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper input validation (CVE-ID: CVE-2026-68219)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in the imx8-isi scaling configuration logic when processing crafted image scaling parameters. A local user can supply specially crafted width or height values to cause a denial of service.
The issue can cause the affected process to stop responding even when interrupted with Ctrl+C.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/28ae75dba701d7aa69a36802c398582933d3e0e6
- https://git.kernel.org/stable/c/57a7ec5c9f38ce6c4d6209c4b75c8e57e1fea6cf
- https://git.kernel.org/stable/c/690cdda752f3dc6b7a8b2d4a243e0207b66a1f37
- https://git.kernel.org/stable/c/75cdfaa7c908ca06d564170da9c80fb579f149a5
- https://git.kernel.org/stable/c/ba7e1b06cbdad3b7c3314390cca22aff42f655d4