
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-31655 is a vulnerability in the Linux kernel's pmdomain: imx8mp-blk-ctrl module caused by the NOC_HDCP clock not being kept enabled, which can result in system hangs during the NoC ADB400 port power-down handshake. It affects Linux kernel versions 6.1.1 through 6.6.134, 6.7 through 6.12.81, 6.13 through 6.18.22, and 6.19 through 6.19.12, as well as pre-release 7.0 release candidates. The vulnerability was published on April 24, 2026. It carries a CVSS v3.1 base score of 5.5 (Medium), with a local attack vector and high availability impact (GitHub Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-413 (Improper Resource Locking): the imx8mp-blk-ctrl power domain driver fails to keep the NOC_HDCP clock always enabled, which is required to maintain proper synchronization during the NoC ADB400 port power-down handshake sequence on NXP i.MX8MP SoCs. When the clock is not held active, the handshake can stall indefinitely, causing a system hang. Exploitation requires local access with low privileges and no user interaction. The fix, applied across multiple stable kernel branches, ensures the NOC_HDCP clock is unconditionally enabled to prevent the race condition (GitHub Advisory, Red Hat Bugzilla).
Successful triggering of this vulnerability results in a system hang (denial of service) on i.MX8MP-based hardware, with high availability impact and no confidentiality or integrity impact. The affected scope is limited to systems using the NXP i.MX8MP SoC running vulnerable Linux kernel versions, particularly those that exercise power domain transitions involving the NoC ADB400 port. There is no known potential for lateral movement or data exposure (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.018% (0.000180), indicating very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation is limited to local, low-privileged users on i.MX8MP hardware, significantly constraining the attack surface (GitHub Advisory).
Update to a patched Linux kernel version: 6.6.135 or later, 6.12.82 or later, 6.18.23 or later, 6.19.13 or later, or 7.0 and later. Patches are available in upstream Linux kernel stable commits. Administrators running i.MX8MP-based systems should prioritize applying kernel updates through their Linux distribution's standard update mechanism. No configuration-based workaround is documented; upgrading is the recommended remediation (GitHub Advisory, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."