Impact
The atlas sensor driver in the Linux kernel acquires a runtime power‑management reference during buffer post‑enable, but the reference is not released if the interrupt configuration fails. The unreleased reference causes the device to never enter autosuspend, resulting in continued power usage and the potential for battery drainage or increased system power draw, which constitutes a denial‑of‑service condition. No mechanism exists for an attacker to gain code execution or arbitrary system compromise from this flaw.
Affected Systems
Any Linux kernel that includes the atlas sensor driver – part of the IIO chemical subsystem – is affected. The issue is not limited to a specific distribution or configuration; all builds containing the legacy atlas driver before the patch may experience the reference leak.
Risk and Exploitability
The EPSS score is reported as less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. The flaw is triggered during device initialization, so an attacker would need to cause the interrupt configuration to fail, which is unlikely to be easily controllable. Given the low exploitation likelihood but the impact on power management, the overall risk remains moderate, but the patch should be applied promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA