Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-89939
Published: September 17, 2026
Vulnerability identifier: #VU150346
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89939
CWE-ID: CWE-772
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to prevent the device from autosuspending.
The vulnerability exists due to a missing release of a runtime PM reference in atlas_buffer_postenable() when enabling an IIO buffer and interrupt configuration fails. A local user can enable an IIO buffer to prevent the device from autosuspending.
Affected software
Linux kernel
How to mitigate CVE-2026-89939
Install security update from vendor's repository.
Linux kernel - update to 7.0 rc3
External References
- https://git.kernel.org/stable/c/43bce901047e95bbf8fb63eb471460642e497604
- https://git.kernel.org/stable/c/72daa7eb7fc6202fece0bb56487d72af5c49ccdf
- https://git.kernel.org/stable/c/777e8ebfe6b3fa733694977f0f4cf849e07e925c
- https://git.kernel.org/stable/c/a595f4d3e4ee1c91c62a298730a77b16dc26b426
- https://git.kernel.org/stable/c/aedf8f068d9da774d5cb62e9c9d6e62b2ce64d86
- https://git.kernel.org/stable/c/bcd3f72e26314edfce7eaf8d7160b3119c7b7fed
- https://git.kernel.org/stable/c/c7e91ae6d7802170f53ece09a4ecc6302265d3e4