Impact
In the Linux kernel IIO pressure driver for the MPL115 sensor, the routine that reads raw data incorrectly handles its runtime power management reference. Although it acquires a reference before initiating a read, it fails to release the reference when an error occurs, leaving the device unable to autosuspend. The unchecked reference accumulates with each erroneous read, spiralling into a resource exhaustion scenario that can degrade kernel responsiveness and overall system stability.*
Affected Systems
This issue affects Linux systems that include the IIO framework and the MPL115 pressure sensor driver. All kernel versions prior to the fix are susceptible. The vulnerability is defined by commits in the Linux kernel repository and has been resolved in the most recent kernel releases.*
Risk and Exploitability
The EPSS score indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation would likely require repeated sensor read errors, which are typically triggered by application activity rather than an external attacker. The missing CVSS score limits a precise severity assessment, but the resource leak can lead to denial‑of‑service conditions if not addressed.*
OpenCVE Enrichment
Debian DLA
Debian DSA