Improper control of a resource through its lifetime in Linux kernel - CVE-2026-90249
Published: September 18, 2026
Vulnerability identifier: #VU151227
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90249
CWE-ID: CWE-664
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper runtime power-management reference handling in the gp2ap002_write_event_config() function when writing duplicate event enable values. A local user can write the same event enable state twice to cause a denial of service.
Affected software
Linux kernel
How to mitigate CVE-2026-90249
Install security update from vendor's repository.
External References
- https://git.kernel.org/stable/c/0fc740c25c9abb25113398ebb58e2f2ce57741a7
- https://git.kernel.org/stable/c/470edb012b1d9a4fba1cd59e329e60f0798c791a
- https://git.kernel.org/stable/c/56fe8e5f313a64e458bb6f8b982de925345e21a7
- https://git.kernel.org/stable/c/579c049b4cb6fc72ce2c505fc5334540be0efcd3
- https://git.kernel.org/stable/c/685d9d1e5c47e024413981fb7eddab86132b04a1
- https://git.kernel.org/stable/c/70b9482926ca92862460e659f5e5fde99ae0b4fa
- https://git.kernel.org/stable/c/8e76ab81319858736ccf23141e9415f9a1869337
- https://git.kernel.org/stable/c/b2d7a97d75b648a643f60d77f4d6d70161268855