CVE-2026-90249

Source
https://cve.org/CVERecord?id=CVE-2026-90249
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90249.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90249
Downstream
Published
2026-09-17T16:07:50Z
Modified
2026-09-18T03:48:36Z
Summary
iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes
Details

In the Linux kernel, the following vulnerability has been resolved:

iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes

The IIO core does not filter duplicate writes to the event enable attribute, so writing the same value twice invokes write_event_config() twice. Enabling twice leaks a runtime PM reference, preventing the device from ever suspending again; disabling twice underflows the usage count and triggers a "Runtime PM usage count underflow" warning.

Bail out early when the requested state matches the current state. While at it, switch to pm_runtime_resume_and_get() so a failed resume is propagated to userspace instead of silently marking the event enabled.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90249.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
97d642e23037c5545266f9564c9b81e6db81b122
Fixed
b2d7a97d75b648a643f60d77f4d6d70161268855
Fixed
685d9d1e5c47e024413981fb7eddab86132b04a1
Fixed
56fe8e5f313a64e458bb6f8b982de925345e21a7
Fixed
8e76ab81319858736ccf23141e9415f9a1869337
Fixed
70b9482926ca92862460e659f5e5fde99ae0b4fa
Fixed
0fc740c25c9abb25113398ebb58e2f2ce57741a7
Fixed
470edb012b1d9a4fba1cd59e329e60f0798c791a
Fixed
579c049b4cb6fc72ce2c505fc5334540be0efcd3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90249.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.7.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90249.json"