Impact
The Linux kernel driver for the Texas Instruments ADS1119 analog‑to‑digital converter contains a bug where the PM reference count is increased before initiating a conversion but is not decreased if a subsequent I2C write fails. This results in a leaked reference that keeps the device in a runtime‑active state for an extended period, potentially leading to sustained power usage, overheating, or interference with system power management. The leak does not provide direct remote code execution but can degrade system performance and stability over time.
Affected Systems
All installations of the Linux kernel that include the ADS1119 driver before the bug fix are affected. The vendor/product listing is broadly “Linux kernel”, with no specific version numbers listed in the CNA data. Therefore any distribution using a kernel containing the unpatched driver may be impacted until the patch is applied.
Risk and Exploitability
The CVSS score is not provided and the EPSS score is reported as less than 1%, indicating a very low probability of real‑world exploitation. The vulnerability is not present in the CISA KEV catalog, indicating it has not been widely exploited yet. Based on the description, it is inferred that exploitation would require local access to the I2C interface and the ability to trigger the driver’s buffer pre‑enable routine; it is not a remote or network‑exposed vector. Given the low EPSS and lack of public exploits, the risk level is currently assessed as low, but the impact on power and resource usage warrants timely remediation.
OpenCVE Enrichment
Debian DLA