SB20260918414 - Improper control of a resource through its lifetime in Linux kernel iio light driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-90249)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper runtime power-management reference handling in the gp2ap002_write_event_config() function when writing duplicate event enable values. A local user can write the same event enable state twice to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0fc740c25c9abb25113398ebb58e2f2ce57741a7
- https://git.kernel.org/stable/c/470edb012b1d9a4fba1cd59e329e60f0798c791a
- https://git.kernel.org/stable/c/56fe8e5f313a64e458bb6f8b982de925345e21a7
- https://git.kernel.org/stable/c/579c049b4cb6fc72ce2c505fc5334540be0efcd3
- https://git.kernel.org/stable/c/685d9d1e5c47e024413981fb7eddab86132b04a1
- https://git.kernel.org/stable/c/70b9482926ca92862460e659f5e5fde99ae0b4fa
- https://git.kernel.org/stable/c/8e76ab81319858736ccf23141e9415f9a1869337
- https://git.kernel.org/stable/c/b2d7a97d75b648a643f60d77f4d6d70161268855