Linux Kernel Out-of-Range Access Vulnerability in IMX8M Block Control Driver

Vulnerability

A vulnerability has been identified in the Linux kernel's IMX8M block control driver, specifically in the domain management code. The issue arises from an out-of-range access to the 'bc->domains' array in the 'imx8m_blk_ctrl_remove()' function. This flaw could potentially lead to undefined behavior or memory corruption.

Impact

The vulnerability could cause out-of-bounds memory access, which may lead to memory corruption or undefined behavior in the kernel.

Reproduction

The vulnerability can be reproduced by loading the IMX8M block control driver and then removing it. The 'imx8m_blk_ctrl_remove()' function will be called, which contains the out-of-range access issue.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed.

Added: Feb 14, 2026, 5:32 PM
Updated: Feb 14, 2026, 5:32 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
3.9
remediation
7.7
relevance
3.0
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.