Improper resource shutdown or release in Linux kernel - CVE-2026-89935
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to prevent the device from autosuspending.
The vulnerability exists due to improper resource release in apds9306_read_data() when handling error paths after acquiring a runtime PM reference. A local user can trigger an error path in apds9306_read_data() to prevent the device from autosuspending.