Back to overview

CVE-2026-64494

Description
In the Linux kernel, the following vulnerability has been resolved: iio: light: gp2ap002: fix runtime PM leak on read error gp2ap002_read_raw() calls pm_runtime_get_sync() before reading the lux value, but if gp2ap002_get_lux() fails, it returns directly. This skips the pm_runtime_put_autosuspend() call at the "out" label, permanently leaking a runtime PM reference and preventing the device from autosuspending. Replace the direct return with a "goto out" to ensure the reference is properly dropped on the error path.

Metadata

CVE ID
CVE-2026-64494
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 15:36 UTC
Published
2026-07-25 08:51 UTC
Last updated
2026-07-25 08:51 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux f6dbf83c17cb223ceabd7c42d441414f3e0e8a86 < 62e0d74821a02f0e0c5c79b99ae64dc83a9a90f5, f6dbf83c17cb223ceabd7c42d441414f3e0e8a86 < 7110201c6b21455240c63388f30113f3baafacfc, f6dbf83c17cb223ceabd7c42d441414f3e0e8a86 < 2593f0c6ea37df168975694a3b17e7086f11453e, f6dbf83c17cb223ceabd7c42d441414f3e0e8a86 < f350883989ced96d6da7f582f9a6f9c6ffc94e34 …
Linux Linux 5.8, 0 < 5.8, 5.10.261 ≤ 5.10.*, 5.15.212 ≤ 5.15.* …
Back to overview