Impact
A timing bug in i.MX8MP VC8000E power-domain management can cause a deadlock during power‑up or power‑down cycles. Missing the requirement to clear the VC8000E clock before the first reset allows the VPU_NOC handshake to stall, potentially hanging the entire VPU subsystem and any software that depends on it, which results in a denial of service for video and firmware update functions.
Affected Systems
The flaw is confined to Linux kernels that implement the i.MX power domain driver for i.MX8MP processors. Boards or devices that use the VC8000E block controller and rely on NXP’s i.MX8MP reference platform are susceptible. The affected code is part of the kernel’s imx power‑domain domain, not a specific kernel release, so affected users should inspect whether their kernel tree contains the errata flag or the proper clock sequencing logic.
Risk and Exploitability
The CVSS score of 5.5 represents moderate severity, and the EPSS score of less than 1% indicates a low current exploitation probability. The flaw is not listed in CISA’s KEV catalog. It requires a local action that manipulates the power cycling sequence of the VC8000E, so remote exploitation via a network interface is not feasible. An attacker who can trigger a VC8000E reset through a local firmware interface could force the device into a deadlock, denying service to dependent subsystems.
OpenCVE Enrichment