Impact
The Linux kernel’s staging media driver for the IPU7 device had a reference count leak in the resume callback. The previous implementation incremented the runtime PM usage counter with pm_runtime_get_sync and, on failure, failed to decrement the counter, leaving the runtime PM reference count higher than appropriate. This mismatch can accumulate over time and cause resource exhaustion or degraded performance for the media subsystem. The bug is classified as a resource management defect and can impact the stability of any application that repeatedly suspends and resumes the IPU7 hardware.
Affected Systems
The flaw resides in the Linux kernel’s staging media subsystem for the IPU7 device. All Linux kernel builds that include the staging media IPU7 driver – which is typically packaged with mainstream distributions – are affected. No vendor‑specific product version is identified beyond the generic Linux kernel inclusion.
Risk and Exploitability
The vulnerability has an EPSS score of less than 1 % and is not listed in the CISA KEV catalog, indicating a very low likelihood of exploitation. Because the flaw is an internal reference counter oversight rather than a network‑exposed code execution path, it can be exploited only by code that can drive the driver to repeatedly resume the device, such as privileged applications or kernel modules. There is no known public exploit, and the risk is largely confined to environments that perform frequent resume cycles on the IPU7 hardware. A high CVSS score is not currently assigned, but the indirect impact on system reliability warrants patching as soon as a stable kernel release becomes available.
OpenCVE Enrichment