Linux Kernel Vulnerability in KXSD9 Accelerometer Driver
CVE-2026-64503
What is CVE-2026-64503?
A vulnerability in the Linux kernel's KXSD9 accelerometer driver arises from an improper handling of runtime power management references during error conditions. Specifically, the function 'kxsd9_write_raw()' holds a runtime PM reference but fails to release it upon encountering an error, resulting in a reference leak. This mismanagement can prevent the device from entering an autosuspend state, potentially leading to increased power consumption and operational inefficiencies. The issue was addressed by ensuring that error conditions correctly invoke the existing runtime PM release mechanisms, thereby maintaining system stability and efficiency.
Affected Version(s)
Linux 9a9a369d6178dd4e263c49085ce1b37e1e8f63a0
Linux 9a9a369d6178dd4e263c49085ce1b37e1e8f63a0
Linux 9a9a369d6178dd4e263c49085ce1b37e1e8f63a0 < 191fcfeb729ededd8dd2a999c6bf351ddfa0cec7