CVE-2026-89935

Summary

In the Linux kernel, the following vulnerability has been resolved:

iio: light: apds9306: fix PM reference leak in apds9306_read_data()

apds9306_read_data() calls pm_runtime_resume_and_get() but several error paths return directly without calling pm_runtime_put_autosuspend(), leaking the runtime PM reference and preventing the device from autosuspending.

Use PM_RUNTIME_ACQUIRE_AUTOSUSPEND() and PM_RUNTIME_ACQUIRE_ERR() to automatically handle runtime PM reference release on all return paths.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux620d1e6c7a3fcc54c641f091e07b9040f13def19 < f3d97800b03cd39ec135e544dcd0a93ffd18e4c7affected
LinuxLinux620d1e6c7a3fcc54c641f091e07b9040f13def19 < 3ce75e455dd6eaa775fb0badb31c0b100c7a01feaffected
LinuxLinux620d1e6c7a3fcc54c641f091e07b9040f13def19 < d378fceaafd79e0dc59d3546bda251a3058062c0affected
LinuxLinux6.10affected
LinuxLinux0 < 6.10unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.5 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References