CVE-2026-53340 is a vulnerability in Linux Kernel
Published on July 1, 2026
i2c: imx: fix clock and pinctrl state inconsistency in runtime PM
In the Linux kernel, the following vulnerability has been resolved:
i2c: imx: fix clock and pinctrl state inconsistency in runtime PM
In i2c_imx_runtime_suspend(), the clock is disabled before switching
the pinctrl state to sleep. If pinctrl_pm_select_sleep_state() fails,
the runtime suspend is aborted but the clock remains disabled, causing
a system crash when the hardware is subsequently accessed.
Fix this by switching the pinctrl state before disabling the clock so
that a pinctrl failure leaves the clock enabled and the hardware
accessible.
In i2c_imx_runtime_resume(), restore the pinctrl state back to sleep
if clk_enable() fails to keep the consistent.
Products Associated with CVE-2026-53340
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 576eba03c99435380d155e5f71d5d7603b9178f6 and below 9fa82cf393bafc7bd7ca15c1d5cbd5b57ab9de1d is affected.
- Version 576eba03c99435380d155e5f71d5d7603b9178f6 and below c8f5269c1bf505847bc7dbb92054594790114de6 is affected.
- Version 576eba03c99435380d155e5f71d5d7603b9178f6 and below 8783fb8031799f1230997c16df8c8dce9fcd1841 is affected.
- Version 6.14 is affected.
- Before 6.14 is unaffected.
- Version 6.18.36, <= 6.18.* is unaffected.
- Version 7.0.13, <= 7.0.* is unaffected.
- Version 7.1, <= * is unaffected.