Description
In the Linux kernel, the following vulnerability has been resolved:

staging: media: ipu7: fix pm_runtime refcount leak in ipu7_resume()

ipu7_resume() calls pm_runtime_get_sync() before resuming the device.
If the runtime PM resume fails, the usage count remains incremented, but
the error path returns without dropping the reference.

Use pm_runtime_resume_and_get() instead, which balances the usage count
on failure and avoids the leak. Keep returning 0 on error, as resume
callbacks should not propagate failures to the PM core, matching the
behaviour of the ipu6 driver.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Reference count leak in IPU7 media driver could lead to resource exhaustion or application instability
Action: Patch
AI Analysis

Impact

The Linux kernel’s staging media driver for the IPU7 device had a reference count leak in the resume callback. The previous implementation incremented the runtime PM usage counter with pm_runtime_get_sync and, on failure, failed to decrement the counter, leaving the runtime PM reference count higher than appropriate. This mismatch can accumulate over time and cause resource exhaustion or degraded performance for the media subsystem. The bug is classified as a resource management defect and can impact the stability of any application that repeatedly suspends and resumes the IPU7 hardware.

Affected Systems

The flaw resides in the Linux kernel’s staging media subsystem for the IPU7 device. All Linux kernel builds that include the staging media IPU7 driver – which is typically packaged with mainstream distributions – are affected. No vendor‑specific product version is identified beyond the generic Linux kernel inclusion.

Risk and Exploitability

The vulnerability has an EPSS score of less than 1 % and is not listed in the CISA KEV catalog, indicating a very low likelihood of exploitation. Because the flaw is an internal reference counter oversight rather than a network‑exposed code execution path, it can be exploited only by code that can drive the driver to repeatedly resume the device, such as privileged applications or kernel modules. There is no known public exploit, and the risk is largely confined to environments that perform frequent resume cycles on the IPU7 hardware. A high CVSS score is not currently assigned, but the indirect impact on system reliability warrants patching as soon as a stable kernel release becomes available.

Generated by OpenCVE AI on September 19, 2026 at 07:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Linux kernel patch that replaces pm_runtime_get_sync with pm_runtime_resume_and_get in the ipu7_resume() callback, as referenced in the commit diff links.
  • Verify that the patch correctly balances the runtime PM usage counter on both success and failure paths and that the driver continues to return 0 on resume errors, matching the behavior of IPU6.
  • If immediate kernel upgrade is not possible, monitor the system for increased PM usage counts on the ipu7 device and consider disabling runtime PM for that device via firmware or sysfs parameters until a patched kernel can be deployed.

Generated by OpenCVE AI on September 19, 2026 at 07:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-404

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: staging: media: ipu7: fix pm_runtime refcount leak in ipu7_resume() ipu7_resume() calls pm_runtime_get_sync() before resuming the device. If the runtime PM resume fails, the usage count remains incremented, but the error path returns without dropping the reference. Use pm_runtime_resume_and_get() instead, which balances the usage count on failure and avoids the leak. Keep returning 0 on error, as resume callbacks should not propagate failures to the PM core, matching the behaviour of the ipu6 driver.
Title staging: media: ipu7: fix pm_runtime refcount leak in ipu7_resume()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:42.099Z

Reserved: 2026-09-17T16:02:15.088Z

Link: CVE-2026-93143

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:09.397

Modified: 2026-09-17T17:18:09.397

Link: CVE-2026-93143

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:00:11Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release