CVE-2026-68280
Received Received - Intake

Clock Framework Warning in Cadence DSI Bridge

Vulnerability report for CVE-2026-68280, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() The deprecated UNIVERSAL_DEV_PM_OPS() macro uses the provided callbacks for both runtime PM and system sleep. This causes the DSI clocks to be disabled twice: once during runtime suspend and again during system suspend, resulting in a WARN message from the clock framework when attempting to disable already-disabled clocks. [ 84.384540] clk:231:5 already disabled [ 84.388314] WARNING: CPU: 2 PID: 531 at /drivers/clk/clk.c:1181 clk_core_disable+0xa4/0xac ... [ 84.579183] Call trace: [ 84.581624] clk_core_disable+0xa4/0xac [ 84.585457] clk_disable+0x30/0x4c [ 84.588857] cdns_dsi_suspend+0x20/0x58 [cdns_dsi] [ 84.593651] pm_generic_suspend+0x2c/0x44 [ 84.597661] ti_sci_pd_suspend+0xbc/0x15c [ 84.601670] dpm_run_callback+0x8c/0x14c [ 84.605588] __device_suspend+0x1a0/0x56c [ 84.609594] dpm_suspend+0x17c/0x21c [ 84.613165] dpm_suspend_start+0xa0/0xa8 [ 84.617083] suspend_devices_and_enter+0x12c/0x634 [ 84.621872] pm_suspend+0x1fc/0x368 To address this issue, replace UNIVERSAL_DEV_PM_OPS() with RUNTIME_PM_OPS(). Bridge and panel drivers should only deal with runtime PM, as the DRM framework manages system-wide power transitions through the bridge enable() and disable() hooks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux_kernel linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves the deprecated UNIVERSAL_DEV_PM_OPS() macro in the drm/bridge/cdns-dsi driver. It causes DSI clocks to be disabled twice during runtime suspend and system suspend, leading to a warning from the clock framework when attempting to disable already-disabled clocks.

Detection Guidance

This vulnerability is specific to the Linux kernel's DRM bridge subsystem and may manifest as a warning in kernel logs when DSI clocks are disabled twice. Check kernel logs for messages like 'clk: already disabled' or 'WARNING: CPU: ... clk_core_disable' using commands like 'dmesg | grep -i clk' or 'journalctl -k | grep -i clk'.

Impact Analysis

This vulnerability may cause system instability or unexpected warnings during suspend operations. It could lead to improper power management in systems using the affected Linux kernel driver, potentially causing crashes or reduced performance.

Mitigation Strategies

Apply the kernel patch that replaces UNIVERSAL_DEV_PM_OPS() with RUNTIME_PM_OPS() in the cdns-dsi driver. Update to a kernel version containing this fix or manually patch the affected driver code.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68280. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart