Impact
The Linux kernel’s gp2ap002 IIO light driver does not filter duplicate writes to the event enable attribute, causing write_event_config() to be invoked twice. This double invocation leaks a runtime power‑management reference so the device cannot suspend, and can under‑flow the counter if disabled twice, triggering a runtime PM usage count underflow warning. The exploit could allow a local privilege user to generate repeated writes and force the device to stay active, draining power or rendering the system unable to enter low‑power states. The issue arises when an attacker has access to the device node controlling the event attribute, which typically requires elevated privileges; it is inferred that privileged local users could potentially abuse this scenario.
Affected Systems
Affected products are all Linux kernel releases before the patch commit. No specific kernel version range is provided, so any system running a kernel version prior to the fix is considered vulnerable.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in CISA KEV, indicating low current exploitation probability. However, the problem requires only sporadic writes from a local privileged context; it is inferred that the attack vector is local privilege, so an attacker who can gain such access could cause a denial of service by preventing suspend and leaking resources. The CVSS score is not provided here; the impact suggests a high severity over a local scope.
OpenCVE Enrichment
Debian DLA
Debian DSA