{"api_version":"1","generated_at":"2026-08-01T23:14:37+00:00","cve":"CVE-2026-64499","urls":{"html":"https://cve.report/CVE-2026-64499","api":"https://cve.report/api/cve/CVE-2026-64499.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-64499","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-64499"},"summary":{"title":"iio: adc: ti-ads1119: fix PM reference leak in buffer preenable","description":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: ti-ads1119: fix PM reference leak in buffer preenable\n\nads1119_triggered_buffer_preenable() resumes the device with\npm_runtime_resume_and_get() before starting a conversion.\n\nIf i2c_smbus_write_byte() fails, the function returns the error directly\nand leaves the runtime PM usage counter elevated. The matching\npostdisable callback is not called when preenable fails, so the reference\nis leaked and the device may remain runtime-active indefinitely.\n\nStore the I2C transfer result in ret and drop the runtime PM reference on\nfailure before returning the error.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-07-25 10:17:35","updated_at":"2026-07-25 10:17:35"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/f40292fb19399a3c3f82de698023ba87c01e66cf","name":"https://git.kernel.org/stable/c/f40292fb19399a3c3f82de698023ba87c01e66cf","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/ffb2195921c3d629194b9807de589578df9f9cb8","name":"https://git.kernel.org/stable/c/ffb2195921c3d629194b9807de589578df9f9cb8","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/adf4bc07f814da8329278d32600147f5a150938c","name":"https://git.kernel.org/stable/c/adf4bc07f814da8329278d32600147f5a150938c","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/6537f08100189d12bec4975000244e6ac4873c28","name":"https://git.kernel.org/stable/c/6537f08100189d12bec4975000244e6ac4873c28","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64499","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64499","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a9306887eba41c5fe7232727a8147da3d3c4f83c f40292fb19399a3c3f82de698023ba87c01e66cf git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a9306887eba41c5fe7232727a8147da3d3c4f83c ffb2195921c3d629194b9807de589578df9f9cb8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a9306887eba41c5fe7232727a8147da3d3c4f83c 6537f08100189d12bec4975000244e6ac4873c28 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a9306887eba41c5fe7232727a8147da3d3c4f83c adf4bc07f814da8329278d32600147f5a150938c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.11","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.11 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.96 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.39 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.4 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2-rc3 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"64499","cve":"CVE-2026-64499","epss":"0.001570000","percentile":"0.053080000","score_date":"2026-07-28","updated_at":"2026-07-29 00:05:33"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/iio/adc/ti-ads1119.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"f40292fb19399a3c3f82de698023ba87c01e66cf","status":"affected","version":"a9306887eba41c5fe7232727a8147da3d3c4f83c","versionType":"git"},{"lessThan":"ffb2195921c3d629194b9807de589578df9f9cb8","status":"affected","version":"a9306887eba41c5fe7232727a8147da3d3c4f83c","versionType":"git"},{"lessThan":"6537f08100189d12bec4975000244e6ac4873c28","status":"affected","version":"a9306887eba41c5fe7232727a8147da3d3c4f83c","versionType":"git"},{"lessThan":"adf4bc07f814da8329278d32600147f5a150938c","status":"affected","version":"a9306887eba41c5fe7232727a8147da3d3c4f83c","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/iio/adc/ti-ads1119.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.11"},{"lessThan":"6.11","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.96","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.39","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.4","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2-rc3","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.96","versionStartIncluding":"6.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.39","versionStartIncluding":"6.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.4","versionStartIncluding":"6.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2-rc3","versionStartIncluding":"6.11","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: ti-ads1119: fix PM reference leak in buffer preenable\n\nads1119_triggered_buffer_preenable() resumes the device with\npm_runtime_resume_and_get() before starting a conversion.\n\nIf i2c_smbus_write_byte() fails, the function returns the error directly\nand leaves the runtime PM usage counter elevated. The matching\npostdisable callback is not called when preenable fails, so the reference\nis leaked and the device may remain runtime-active indefinitely.\n\nStore the I2C transfer result in ret and drop the runtime PM reference on\nfailure before returning the error."}],"providerMetadata":{"dateUpdated":"2026-07-25T08:51:55.336Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/f40292fb19399a3c3f82de698023ba87c01e66cf"},{"url":"https://git.kernel.org/stable/c/ffb2195921c3d629194b9807de589578df9f9cb8"},{"url":"https://git.kernel.org/stable/c/6537f08100189d12bec4975000244e6ac4873c28"},{"url":"https://git.kernel.org/stable/c/adf4bc07f814da8329278d32600147f5a150938c"}],"title":"iio: adc: ti-ads1119: fix PM reference leak in buffer preenable","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-64499","datePublished":"2026-07-25T08:51:55.336Z","dateReserved":"2026-07-19T15:36:31.793Z","dateUpdated":"2026-07-25T08:51:55.336Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-25 10:17:35","lastModifiedDate":"2026-07-25 10:17:35","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"64499","Ordinal":"1","Title":"iio: adc: ti-ads1119: fix PM reference leak in buffer preenable","CVE":"CVE-2026-64499","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"64499","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: ti-ads1119: fix PM reference leak in buffer preenable\n\nads1119_triggered_buffer_preenable() resumes the device with\npm_runtime_resume_and_get() before starting a conversion.\n\nIf i2c_smbus_write_byte() fails, the function returns the error directly\nand leaves the runtime PM usage counter elevated. The matching\npostdisable callback is not called when preenable fails, so the reference\nis leaked and the device may remain runtime-active indefinitely.\n\nStore the I2C transfer result in ret and drop the runtime PM reference on\nfailure before returning the error.","Type":"Description","Title":"iio: adc: ti-ads1119: fix PM reference leak in buffer preenable"}]}}}