iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes
Summary
| CVE | CVE-2026-90249 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 17:17:21 UTC |
| Updated | 2026-09-17 17:17:21 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes
The IIO core does not filter duplicate writes to the event enable
attribute, so writing the same value twice invokes
write_event_config() twice. Enabling twice leaks a runtime PM
reference, preventing the device from ever suspending again;
disabling twice underflows the usage count and triggers a
"Runtime PM usage count underflow" warning.
Bail out early when the requested state matches the current state.
While at it, switch to pm_runtime_resume_and_get() so a failed
resume is propagated to userspace instead of silently marking the
event enabled. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 97d642e23037c5545266f9564c9b81e6db81b122 b2d7a97d75b648a643f60d77f4d6d70161268855 git |
Not specified |
| CNA |
Linux |
Linux |
affected 97d642e23037c5545266f9564c9b81e6db81b122 685d9d1e5c47e024413981fb7eddab86132b04a1 git |
Not specified |
| CNA |
Linux |
Linux |
affected 97d642e23037c5545266f9564c9b81e6db81b122 56fe8e5f313a64e458bb6f8b982de925345e21a7 git |
Not specified |
| CNA |
Linux |
Linux |
affected 97d642e23037c5545266f9564c9b81e6db81b122 8e76ab81319858736ccf23141e9415f9a1869337 git |
Not specified |
| CNA |
Linux |
Linux |
affected 97d642e23037c5545266f9564c9b81e6db81b122 70b9482926ca92862460e659f5e5fde99ae0b4fa git |
Not specified |
| CNA |
Linux |
Linux |
affected 97d642e23037c5545266f9564c9b81e6db81b122 0fc740c25c9abb25113398ebb58e2f2ce57741a7 git |
Not specified |
| CNA |
Linux |
Linux |
affected 97d642e23037c5545266f9564c9b81e6db81b122 470edb012b1d9a4fba1cd59e329e60f0798c791a git |
Not specified |
| CNA |
Linux |
Linux |
affected 97d642e23037c5545266f9564c9b81e6db81b122 579c049b4cb6fc72ce2c505fc5334540be0efcd3 git |
Not specified |
| CNA |
Linux |
Linux |
affected 5.7 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.7 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.10.270 5.10.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15.221 5.15.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.188 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.157 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.110 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.52 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.6 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/b2d7a97d75b648a643f60d77f4d6d70161268855 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/56fe8e5f313a64e458bb6f8b982de925345e21a7 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/470edb012b1d9a4fba1cd59e329e60f0798c791a |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/579c049b4cb6fc72ce2c505fc5334540be0efcd3 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/8e76ab81319858736ccf23141e9415f9a1869337 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/70b9482926ca92862460e659f5e5fde99ae0b4fa |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/0fc740c25c9abb25113398ebb58e2f2ce57741a7 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/685d9d1e5c47e024413981fb7eddab86132b04a1 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.