Description
In the Linux kernel, the following vulnerability has been resolved:

iio: light: apds9306: fix PM reference leak in apds9306_read_data()

apds9306_read_data() calls pm_runtime_resume_and_get() but several
error paths return directly without calling pm_runtime_put_autosuspend(),
leaking the runtime PM reference and preventing the device from
autosuspending.

Use PM_RUNTIME_ACQUIRE_AUTOSUSPEND() and PM_RUNTIME_ACQUIRE_ERR() to
automatically handle runtime PM reference release on all return paths.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Runtime PM reference leak that prevents device autosuspend and can lead to resource exhaustion
Action: Apply patch
AI Analysis

Impact

The kernel’s apds9306 driver has a runtime power‑management reference leak: when apds9306_read_data() encounters an error, it exits without releasing the PM reference acquired by pm_runtime_resume_and_get(). This failure to call pm_runtime_put_autosuspend() blocks the device from autosuspending, meaning the driver keeps the device powered on indefinitely. The resulting denial of service could manifest as excessive power consumption or memory pressure due to the lingering reference count.

Affected Systems

All Linux kernel users of the apds9306 light sensor driver are affected, regardless of distribution, as the flaw resides in the kernel source code itself. No specific version range is listed, so any kernel build that includes the unpatched apds9306 driver is potentially vulnerable.

Risk and Exploitability

The EPSS score indicates an exploitation probability of less than 1 %. The vulnerability is not currently catalogued in the CISA KEV list. An attacker would likely need local access that allows invoking the device’s read interface, which could be similar to physical or low‑privilege attacks. Because the leak is tied to normal operation, preventing autosuspend can degrade device reliability but is unlikely to permit remote code execution or privilege escalation. The risk is therefore moderate, primarily a denial‑of‑service and resource‑consumption concern rather than a direct security breach.

Generated by OpenCVE AI on September 18, 2026 at 07:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that includes the patched apds9306 driver, ensuring the pm_runtime reference is correctly released on all code paths.
  • If an immediate kernel upgrade is not feasible, limit exposure by disabling the apds9306 device or removing the driver from the system, thereby preventing the reference leak from occurring.
  • Configure the runtime power management to be more aggressive—reduce the autosuspend delay or disable autosuspend for the device—so that even if the reference leak persists, the device will not stay powered on for extended periods.
  • Monitor the runtime PM state of the device under load to ensure it is suspending as intended after the patch is applied.

Generated by OpenCVE AI on September 18, 2026 at 07:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-775

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iio: light: apds9306: fix PM reference leak in apds9306_read_data() apds9306_read_data() calls pm_runtime_resume_and_get() but several error paths return directly without calling pm_runtime_put_autosuspend(), leaking the runtime PM reference and preventing the device from autosuspending. Use PM_RUNTIME_ACQUIRE_AUTOSUSPEND() and PM_RUNTIME_ACQUIRE_ERR() to automatically handle runtime PM reference release on all return paths.
Title iio: light: apds9306: fix PM reference leak in apds9306_read_data()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:24.921Z

Reserved: 2026-09-11T19:38:34.776Z

Link: CVE-2026-89935

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:02.910

Modified: 2026-09-16T11:17:02.910

Link: CVE-2026-89935

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:00:06Z

Weaknesses
  • CWE-775

    Missing Release of File Descriptor or Handle after Effective Lifetime