CVE-2026-68466
DMA timeout bug in Linux lpc32xx_slc NAND driver can cause kernel memory corruption.
Is CVE-2026-68466 being exploited?
Not confirmed. CVE-2026-68466 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.13% probability of exploitation in the next 30 days.
How severe is CVE-2026-68466?
CVE-2026-68466 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-68466?
Yes. A fix has been recorded for CVE-2026-68466. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-68466 affect?
CVE-2026-68466 affects Linux kernel (lpc32xx_slc rawnand driver), Embedded devices using LPC32xx SoC, Appliances/routers with affected kernels. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-68466?
Apply vendor/kernel patch or update firmware to patched kernel.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Timed-out DMA can access unmapped buffers causing kernel memory corruption, crashes, data corruption, and possible local privilege escalation.
Patch when possible
- affected>= 2944a44da09e46b6db2fd2c3334f242b09e05c43 and < 307e4f4c1d4e1575b3495ecc6e41aa2adc40f491
- affected>= 2944a44da09e46b6db2fd2c3334f242b09e05c43 and < c367af37ce7238c96c6071337149099467160746
- affected>= 2944a44da09e46b6db2fd2c3334f242b09e05c43 and < 623c4d8e740debb4af28981e3d4e209f9d0260a4
- affected>= 2944a44da09e46b6db2fd2c3334f242b09e05c43 and < bd4a622786f92e1f183f7557ab89dd32891cef60
- affected>= 2944a44da09e46b6db2fd2c3334f242b09e05c43 and < 8f5c3ee53a5dc1a0f7cfd780485f2c8b5d17f91d
- affected>= 2944a44da09e46b6db2fd2c3334f242b09e05c43 and < cf7258f57d18026b8f77c0e80ff1805e9caf7250
- affected>= 2944a44da09e46b6db2fd2c3334f242b09e05c43 and < cb2031f8b226efbd13735c07b075e5f14ec11f6d
- affected>= 2944a44da09e46b6db2fd2c3334f242b09e05c43 and < 17a8ce84964f243c8f89dc7353ac7e8d3137bc74
- affected3.7
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.