CVE-2026-64493 (GCVE-0-2026-64493)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: iio: pressure: mpl115: fix runtime PM leak on read error mpl115_read_raw() takes a runtime PM reference with pm_runtime_get_sync() before reading the processed pressure or raw temperature, but on the read error path it returns without calling pm_runtime_put_autosuspend(). Each failed read therefore leaks a runtime PM reference and prevents the device from autosuspending. Drop the reference before checking the return value so both the success and error paths are balanced.
Impacted products
Vendor Product Version
Linux Linux Version: 0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a
Version: 0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a
Version: 0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a
Version: 0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a
Version: 0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/iio/pressure/mpl115.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "5022f4ed5aae974ec530e3cbf0bd223be13055f7",
              "status": "affected",
              "version": "0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a",
              "versionType": "git"
            },
            {
              "lessThan": "aab0fed636b14a5fd52fcae58b484f1cb96b841d",
              "status": "affected",
              "version": "0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a",
              "versionType": "git"
            },
            {
              "lessThan": "b3f1af4ba8e9cf33aa08c4cdcaa5a17b140521ec",
              "status": "affected",
              "version": "0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a",
              "versionType": "git"
            },
            {
              "lessThan": "46e69d3dd429b33e50e2731913239f6af4ea2705",
              "status": "affected",
              "version": "0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a",
              "versionType": "git"
            },
            {
              "lessThan": "fbe67ff37a6fd855a6c097f84f3738bd13d0a898",
              "status": "affected",
              "version": "0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/iio/pressure/mpl115.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.2"
            },
            {
              "lessThan": "6.2",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.39",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.1.*",
              "status": "unaffected",
              "version": "7.1.4",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.145",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.97",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.39",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1.4",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: pressure: mpl115: fix runtime PM leak on read error\n\nmpl115_read_raw() takes a runtime PM reference with pm_runtime_get_sync()\nbefore reading the processed pressure or raw temperature, but on the read\nerror path it returns without calling pm_runtime_put_autosuspend(). Each\nfailed read therefore leaks a runtime PM reference and prevents the device\nfrom autosuspending.\n\nDrop the reference before checking the return value so both the success\nand error paths are balanced."
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-17T04:56:41.512Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5022f4ed5aae974ec530e3cbf0bd223be13055f7"
        },
        {
          "url": "https://git.kernel.org/stable/c/aab0fed636b14a5fd52fcae58b484f1cb96b841d"
        },
        {
          "url": "https://git.kernel.org/stable/c/b3f1af4ba8e9cf33aa08c4cdcaa5a17b140521ec"
        },
        {
          "url": "https://git.kernel.org/stable/c/46e69d3dd429b33e50e2731913239f6af4ea2705"
        },
        {
          "url": "https://git.kernel.org/stable/c/fbe67ff37a6fd855a6c097f84f3738bd13d0a898"
        }
      ],
      "title": "iio: pressure: mpl115: fix runtime PM leak on read error",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-64493",
    "datePublished": "2026-07-25T08:51:51.036Z",
    "dateReserved": "2026-07-19T15:36:31.792Z",
    "dateUpdated": "2026-08-17T04:56:41.512Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…