Description
In the Linux kernel, the following vulnerability has been resolved:

media: i2c: imx415: Release runtime PM reference on VBLANK error

The VBLANK path returned immediately when programming VMAX failed after
pm_runtime_get_if_in_use() had taken a runtime PM reference. Break out of
the switch instead so the common pm_runtime_put() path is used.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Leak
Action: Patch Immediately
AI Analysis

Impact

The vulnerability exists in the Linux kernel's imx415 media/i2c driver. During the VBLANK operation, if configuring VMAX fails after a runtime PM reference has been acquired, the driver mistakenly returns early and fails to release that reference. This results in a PM reference leak; repeated misuse of the VBLANK path can accumulate unreleased references, potentially degrading kernel performance or causing instability. The description does not mention an explicit denial of service, so the impact is limited to a resource leak and possible kernel instability.

Affected Systems

The flaw resides in the Linux kernel’s media/i2c imx415 driver. Any kernel version that includes this driver before the patch is potentially affected, regardless of distribution. No specific version range is given, so all kernels with the imx415 module are at risk until updated.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. The CVSS score is not provided in the source data; based on the described mechanism the likely attack vector is local kernel execution. There is no evidence that an attacker could force a denial‑of‑service or other malicious outcome beyond the resource leak. As a result, risk is considered low while the vulnerability remains unpatched.

Generated by OpenCVE AI on September 18, 2026 at 09:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that contains the imx415 runtime PM reference fix or apply the patch from the provided Git references.
  • If an immediate kernel upgrade is not feasible, disable the imx415 driver or avoid operations that trigger the VBLANK path until a patch can be applied.
  • If the system maintains custom kernel sources, apply the patch to the kernel source tree directly and rebuild the kernel to incorporate the fix.

Generated by OpenCVE AI on September 18, 2026 at 09:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: i2c: imx415: Release runtime PM reference on VBLANK error The VBLANK path returned immediately when programming VMAX failed after pm_runtime_get_if_in_use() had taken a runtime PM reference. Break out of the switch instead so the common pm_runtime_put() path is used.
Title media: i2c: imx415: Release runtime PM reference on VBLANK error
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:52.597Z

Reserved: 2026-09-11T19:38:34.773Z

Link: CVE-2026-89889

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:57.473

Modified: 2026-09-16T11:16:57.473

Link: CVE-2026-89889

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:00:06Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime