CVE-2026-89939

high

Description

In the Linux kernel, the following vulnerability has been resolved: iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable atlas_buffer_postenable() acquires a runtime PM reference with pm_runtime_resume_and_get() but returns the result of atlas_set_interrupt() directly. If atlas_set_interrupt() fails, the runtime PM reference is leaked and the device can never autosuspend. Add pm_runtime_put_autosuspend() on the error path to balance the reference.

References

https://git.kernel.org/stable/c/c7e91ae6d7802170f53ece09a4ecc6302265d3e4

https://git.kernel.org/stable/c/bcd3f72e26314edfce7eaf8d7160b3119c7b7fed

https://git.kernel.org/stable/c/aedf8f068d9da774d5cb62e9c9d6e62b2ce64d86

https://git.kernel.org/stable/c/a595f4d3e4ee1c91c62a298730a77b16dc26b426

https://git.kernel.org/stable/c/777e8ebfe6b3fa733694977f0f4cf849e07e925c

https://git.kernel.org/stable/c/72daa7eb7fc6202fece0bb56487d72af5c49ccdf

https://git.kernel.org/stable/c/43bce901047e95bbf8fb63eb471460642e497604

Details

Source: Mitre, NVD

Published: 2026-09-16

Updated: 2026-09-16

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity: High

EPSS

EPSS: 0.00205