Description
In the Linux kernel, the following vulnerability has been resolved:

media: qcom: iris: handle runtime PM resume failure in core deinit

Check the return value of pm_runtime_resume_and_get() in
iris_core_deinit().

If runtime PM resume fails, skip hardware power-off operations but
still perform software teardown and state transition. Also skip the
corresponding pm_runtime_put_sync() call to avoid unbalanced runtime
PM references.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Unbalanced Runtime Power Management
Action: Update Kernel
AI Analysis

Impact

The Linux kernel driver for QCA Iris incorrectly handles a failure of pm_runtime_resume_and_get during core deinitialization. When the resume call fails, the driver skips hardware power‑off sequence but still conducts software teardown and state transition, omitting the matching pm_runtime_put_sync. This results in an unbalanced runtime power‑management reference count that can lead to resource leaks or inconsistent device state. The flaw does not provide a direct path to privilege escalation or remote code execution; the impact is limited to stability and resource exhaustion.

Affected Systems

All Linux kernel builds that include the QCA Iris driver are affected. This includes kernel modules where the iris subsystem is compiled in or loaded. The impact applies to any system running a kernel that uses the media: qcom: iris driver.

Risk and Exploitability

The EPSS score is less than 1 %, indicating a very low probability of automated exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The flaw requires the driver to be invoked during deinitialization, which is typically a privileged operation; therefore remote exploitation is unlikely. However, repeated failures in environments with many active iris devices could lead to cumulative resource exhaustion and system instability. The overall risk to organizations is low, but the potential for degraded device reliability warrants timely remediation.

Generated by OpenCVE AI on September 19, 2026 at 13:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel version that contains the iris_core_deinit patch (commit 75d79879e…).
  • If a kernel upgrade cannot be performed immediately, disable the iris driver module (modprobe -r qcom_iris) until the fix is applied.
  • After updating or disabling, review kernel logs for pm_runtime resume failures related to iris to verify the issue has been resolved.

Generated by OpenCVE AI on September 19, 2026 at 13:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-658

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: qcom: iris: handle runtime PM resume failure in core deinit Check the return value of pm_runtime_resume_and_get() in iris_core_deinit(). If runtime PM resume fails, skip hardware power-off operations but still perform software teardown and state transition. Also skip the corresponding pm_runtime_put_sync() call to avoid unbalanced runtime PM references.
Title media: qcom: iris: handle runtime PM resume failure in core deinit
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:34.775Z

Reserved: 2026-09-11T19:38:34.812Z

Link: CVE-2026-90406

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:40.463

Modified: 2026-09-17T17:17:40.463

Link: CVE-2026-90406

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:30:13Z

Weaknesses