Light Sensor Runtime PM Leak in Linux Kernel Affects Multiple Devices
CVE-2026-64494

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 July 2026

What is CVE-2026-64494?

A vulnerability exists in the Linux kernel's gp2ap002 light sensor driver, potentially impacting device performance. The method gp2ap002_read_raw() fails to release a runtime PM reference upon an error in reading the light value. This oversight can prevent the device from entering autosuspend mode, leading to unnecessary power consumption and resource leaks. The issue is mitigated by modifying the error handling path to ensure that the reference is dropped correctly. Users are encouraged to update their Linux kernel to incorporate the fix.

Affected Version(s)

Linux f6dbf83c17cb223ceabd7c42d441414f3e0e8a86 < 62e0d74821a02f0e0c5c79b99ae64dc83a9a90f5

Linux f6dbf83c17cb223ceabd7c42d441414f3e0e8a86 < 7110201c6b21455240c63388f30113f3baafacfc

Linux f6dbf83c17cb223ceabd7c42d441414f3e0e8a86 < 2593f0c6ea37df168975694a3b17e7086f11453e

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.