Impact
The kernel’s apds9306 driver has a runtime power‑management reference leak: when apds9306_read_data() encounters an error, it exits without releasing the PM reference acquired by pm_runtime_resume_and_get(). This failure to call pm_runtime_put_autosuspend() blocks the device from autosuspending, meaning the driver keeps the device powered on indefinitely. The resulting denial of service could manifest as excessive power consumption or memory pressure due to the lingering reference count.
Affected Systems
All Linux kernel users of the apds9306 light sensor driver are affected, regardless of distribution, as the flaw resides in the kernel source code itself. No specific version range is listed, so any kernel build that includes the unpatched apds9306 driver is potentially vulnerable.
Risk and Exploitability
The EPSS score indicates an exploitation probability of less than 1 %. The vulnerability is not currently catalogued in the CISA KEV list. An attacker would likely need local access that allows invoking the device’s read interface, which could be similar to physical or low‑privilege attacks. Because the leak is tied to normal operation, preventing autosuspend can degrade device reliability but is unlikely to permit remote code execution or privilege escalation. The risk is therefore moderate, primarily a denial‑of‑service and resource‑consumption concern rather than a direct security breach.
OpenCVE Enrichment