CVE-2026-90249

Summary

In the Linux kernel, the following vulnerability has been resolved:

iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes

The IIO core does not filter duplicate writes to the event enable attribute, so writing the same value twice invokes write_event_config() twice. Enabling twice leaks a runtime PM reference, preventing the device from ever suspending again; disabling twice underflows the usage count and triggers a "Runtime PM usage count underflow" warning.

Bail out early when the requested state matches the current state. While at it, switch to pm_runtime_resume_and_get() so a failed resume is propagated to userspace instead of silently marking the event enabled.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux97d642e23037c5545266f9564c9b81e6db81b122 < b2d7a97d75b648a643f60d77f4d6d70161268855affected
LinuxLinux97d642e23037c5545266f9564c9b81e6db81b122 < 685d9d1e5c47e024413981fb7eddab86132b04a1affected
LinuxLinux97d642e23037c5545266f9564c9b81e6db81b122 < 56fe8e5f313a64e458bb6f8b982de925345e21a7affected
LinuxLinux97d642e23037c5545266f9564c9b81e6db81b122 < 8e76ab81319858736ccf23141e9415f9a1869337affected
LinuxLinux97d642e23037c5545266f9564c9b81e6db81b122 < 70b9482926ca92862460e659f5e5fde99ae0b4faaffected
LinuxLinux97d642e23037c5545266f9564c9b81e6db81b122 < 0fc740c25c9abb25113398ebb58e2f2ce57741a7affected
LinuxLinux97d642e23037c5545266f9564c9b81e6db81b122 < 470edb012b1d9a4fba1cd59e329e60f0798c791aaffected
LinuxLinux97d642e23037c5545266f9564c9b81e6db81b122 < 579c049b4cb6fc72ce2c505fc5334540be0efcd3affected
LinuxLinux5.7affected
LinuxLinux0 < 5.7unaffected
LinuxLinux5.10.270 <= 5.10.*unaffected
LinuxLinux5.15.221 <= 5.15.*unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References