Description
In the Linux kernel, the following vulnerability has been resolved:

iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable

atlas_buffer_postenable() acquires a runtime PM reference with
pm_runtime_resume_and_get() but returns the result of
atlas_set_interrupt() directly. If atlas_set_interrupt() fails,
the runtime PM reference is leaked and the device can never
autosuspend.

Add pm_runtime_put_autosuspend() on the error path to balance
the reference.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

The atlas sensor driver in the Linux kernel acquires a runtime power‑management reference during buffer post‑enable, but the reference is not released if the interrupt configuration fails. The unreleased reference causes the device to never enter autosuspend, resulting in continued power usage and the potential for battery drainage or increased system power draw, which constitutes a denial‑of‑service condition. No mechanism exists for an attacker to gain code execution or arbitrary system compromise from this flaw.

Affected Systems

Any Linux kernel that includes the atlas sensor driver – part of the IIO chemical subsystem – is affected. The issue is not limited to a specific distribution or configuration; all builds containing the legacy atlas driver before the patch may experience the reference leak.

Risk and Exploitability

The EPSS score is reported as less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. The flaw is triggered during device initialization, so an attacker would need to cause the interrupt configuration to fail, which is unlikely to be easily controllable. Given the low exploitation likelihood but the impact on power management, the overall risk remains moderate, but the patch should be applied promptly.

Generated by OpenCVE AI on September 18, 2026 at 03:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that adds pm_runtime_put_autosuspend() on the error path in atlas_buffer_postenable(); refer to the commit range linked in the CVE references.
  • If an immediate kernel upgrade is not possible, temporarily disable autosuspend for the atlas sensor through its sysfs power interface to prevent the power leak until the patch is applied.
  • Monitor system logs for autosuspend failure messages or persistent device activity after system idle to verify the issue has been resolved.

Generated by OpenCVE AI on September 18, 2026 at 03:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-368

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable atlas_buffer_postenable() acquires a runtime PM reference with pm_runtime_resume_and_get() but returns the result of atlas_set_interrupt() directly. If atlas_set_interrupt() fails, the runtime PM reference is leaked and the device can never autosuspend. Add pm_runtime_put_autosuspend() on the error path to balance the reference.
Title iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:27.704Z

Reserved: 2026-09-11T19:38:34.776Z

Link: CVE-2026-89939

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:03.463

Modified: 2026-09-16T11:17:03.463

Link: CVE-2026-89939

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:15:02Z

Weaknesses
  • CWE-368

    Context Switching Race Condition