Impact
The Linux kernel driver for QCA Iris incorrectly handles a failure of pm_runtime_resume_and_get during core deinitialization. When the resume call fails, the driver skips hardware power‑off sequence but still conducts software teardown and state transition, omitting the matching pm_runtime_put_sync. This results in an unbalanced runtime power‑management reference count that can lead to resource leaks or inconsistent device state. The flaw does not provide a direct path to privilege escalation or remote code execution; the impact is limited to stability and resource exhaustion.
Affected Systems
All Linux kernel builds that include the QCA Iris driver are affected. This includes kernel modules where the iris subsystem is compiled in or loaded. The impact applies to any system running a kernel that uses the media: qcom: iris driver.
Risk and Exploitability
The EPSS score is less than 1 %, indicating a very low probability of automated exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The flaw requires the driver to be invoked during deinitialization, which is typically a privileged operation; therefore remote exploitation is unlikely. However, repeated failures in environments with many active iris devices could lead to cumulative resource exhaustion and system instability. The overall risk to organizations is low, but the potential for degraded device reliability warrants timely remediation.
OpenCVE Enrichment