Light Sensor Runtime PM Leak in Linux Kernel Affects Multiple Devices
CVE-2026-64494
What is CVE-2026-64494?
A vulnerability exists in the Linux kernel's gp2ap002 light sensor driver, potentially impacting device performance. The method gp2ap002_read_raw() fails to release a runtime PM reference upon an error in reading the light value. This oversight can prevent the device from entering autosuspend mode, leading to unnecessary power consumption and resource leaks. The issue is mitigated by modifying the error handling path to ensure that the reference is dropped correctly. Users are encouraged to update their Linux kernel to incorporate the fix.
Affected Version(s)
Linux f6dbf83c17cb223ceabd7c42d441414f3e0e8a86 < 62e0d74821a02f0e0c5c79b99ae64dc83a9a90f5
Linux f6dbf83c17cb223ceabd7c42d441414f3e0e8a86 < 7110201c6b21455240c63388f30113f3baafacfc
Linux f6dbf83c17cb223ceabd7c42d441414f3e0e8a86 < 2593f0c6ea37df168975694a3b17e7086f11453e