CVE-2026-64494EPSS p11.3%
CVE-2026-64494CVE-2026-64494
Description
In the Linux kernel, the following vulnerability has been resolved:
iio: light: gp2ap002: fix runtime PM leak on read error
gp2ap002_read_raw() calls pm_runtime_get_sync() before reading the
lux value, but if gp2ap002_get_lux() fails, it returns directly. This
skips the pm_runtime_put_autosuspend() call at the "out" label,
permanently leaking a runtime PM reference and preventing the device
from autosuspending.
Replace the direct return with a "goto out" to ensure the reference
is properly dropped on the error path.
Scoring
| EPSS | 0.22% probability of exploitation · percentile 11.3% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-17 |