CVE-2026-89939

Source
https://cve.org/CVERecord?id=CVE-2026-89939
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89939.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89939
Downstream
Published
2026-09-16T10:32:27Z
Modified
2026-09-18T03:48:34Z
Summary
iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable
Details

In the Linux kernel, the following vulnerability has been resolved:

iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable

atlas_buffer_postenable() acquires a runtime PM reference with pm_runtime_resume_and_get() but returns the result of atlas_set_interrupt() directly. If atlas_set_interrupt() fails, the runtime PM reference is leaked and the device can never autosuspend.

Add pm_runtime_put_autosuspend() on the error path to balance the reference.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89939.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0e4f336f50debeacd0f81e931e8451f2ae03f685
Fixed
c7e91ae6d7802170f53ece09a4ecc6302265d3e4
Fixed
a595f4d3e4ee1c91c62a298730a77b16dc26b426
Fixed
72daa7eb7fc6202fece0bb56487d72af5c49ccdf
Fixed
aedf8f068d9da774d5cb62e9c9d6e62b2ce64d86
Fixed
43bce901047e95bbf8fb63eb471460642e497604
Fixed
777e8ebfe6b3fa733694977f0f4cf849e07e925c
Fixed
bcd3f72e26314edfce7eaf8d7160b3119c7b7fed

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89939.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.14.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89939.json"