Description
In the Linux kernel, the following vulnerability has been resolved:

iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes

The IIO core does not filter duplicate writes to the event enable
attribute, so writing the same value twice invokes
write_event_config() twice. Enabling twice leaks a runtime PM
reference, preventing the device from ever suspending again;
disabling twice underflows the usage count and triggers a
"Runtime PM usage count underflow" warning.

Bail out early when the requested state matches the current state.
While at it, switch to pm_runtime_resume_and_get() so a failed
resume is propagated to userspace instead of silently marking the
event enabled.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Runtime PM reference leak causing suspension failure and potential denial of service
Action: Apply patch
AI Analysis

Impact

The Linux kernel’s gp2ap002 IIO light driver does not filter duplicate writes to the event enable attribute, causing write_event_config() to be invoked twice. This double invocation leaks a runtime power‑management reference so the device cannot suspend, and can under‑flow the counter if disabled twice, triggering a runtime PM usage count underflow warning. The exploit could allow a local privilege user to generate repeated writes and force the device to stay active, draining power or rendering the system unable to enter low‑power states. The issue arises when an attacker has access to the device node controlling the event attribute, which typically requires elevated privileges; it is inferred that privileged local users could potentially abuse this scenario.

Affected Systems

Affected products are all Linux kernel releases before the patch commit. No specific kernel version range is provided, so any system running a kernel version prior to the fix is considered vulnerable.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in CISA KEV, indicating low current exploitation probability. However, the problem requires only sporadic writes from a local privileged context; it is inferred that the attack vector is local privilege, so an attacker who can gain such access could cause a denial of service by preventing suspend and leaking resources. The CVSS score is not provided here; the impact suggests a high severity over a local scope.

Generated by OpenCVE AI on September 19, 2026 at 15:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the gp2ap002 runtime PM fix
  • Restrict write access to the gp2ap002 event enable attribute to privileged users only
  • If patching is delayed, audit system logs for "Runtime PM usage count underflow" warnings and avoid unnecessary repeated writes to the attribute

Generated by OpenCVE AI on September 19, 2026 at 15:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
CWE-772

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes The IIO core does not filter duplicate writes to the event enable attribute, so writing the same value twice invokes write_event_config() twice. Enabling twice leaks a runtime PM reference, preventing the device from ever suspending again; disabling twice underflows the usage count and triggers a "Runtime PM usage count underflow" warning. Bail out early when the requested state matches the current state. While at it, switch to pm_runtime_resume_and_get() so a failed resume is propagated to userspace instead of silently marking the event enabled.
Title iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:50.766Z

Reserved: 2026-09-11T19:38:34.795Z

Link: CVE-2026-90249

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:21.097

Modified: 2026-09-17T17:17:21.097

Link: CVE-2026-90249

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:15:14Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-772

    Missing Release of Resource after Effective Lifetime