CVE-2026-64493
In the Linux kernel, the following vulnerability has been resolved:
iio: pressure: mpl115: fix runtime PM leak on read error
mpl115_read_raw() takes a runtime PM reference with pm_runtime_get_sync() before reading the processed pressure or raw temperature, but on the read error path it returns without calling pm_runtime_put_autosuspend(). Each failed read therefore leaks a runtime PM reference and prevents the device from autosuspending.
Drop the reference before checking the return value so both the success and error paths are balanced.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/46e69d3dd429b33e50e2731913239f6af4ea2705
- https://git.kernel.org/stable/c/5022f4ed5aae974ec530e3cbf0bd223be13055f7
- https://git.kernel.org/stable/c/aab0fed636b14a5fd52fcae58b484f1cb96b841d
- https://git.kernel.org/stable/c/b3f1af4ba8e9cf33aa08c4cdcaa5a17b140521ec
- https://git.kernel.org/stable/c/fbe67ff37a6fd855a6c097f84f3738bd13d0a898
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-64493",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a",
"lessThan": "5022f4ed5aae974ec530e3cbf0bd223be13055f7",
"versionType": "git"
},
{
"status": "affected",
"version": "0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a",
"lessThan": "aab0fed636b14a5fd52fcae58b484f1cb96b841d",
"versionType": "git"
},
{
"status": "affected",
"version": "0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a",
"lessThan": "b3f1af4ba8e9cf33aa08c4cdcaa5a17b140521ec",
"versionType": "git"
},
{
"status": "affected",
"version": "0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a",
"lessThan": "46e69d3dd429b33e50e2731913239f6af4ea2705",
"versionType": "git"
},
{
"status": "affected",
"version": "0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a",
"lessThan": "fbe67ff37a6fd855a6c097f84f3738bd13d0a898",
"versionType": "git"
}
],
"programFiles": [
"drivers/iio/pressure/mpl115.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.2"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.2",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/iio/pressure/mpl115.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-07-25T10:17:35.120",
"references": [
{
"url": "https://git.kernel.org/stable/c/46e69d3dd429b33e50e2731913239f6af4ea2705",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5022f4ed5aae974ec530e3cbf0bd223be13055f7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/aab0fed636b14a5fd52fcae58b484f1cb96b841d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b3f1af4ba8e9cf33aa08c4cdcaa5a17b140521ec",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fbe67ff37a6fd855a6c097f84f3738bd13d0a898",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: pressure: mpl115: fix runtime PM leak on read error\n\nmpl115_read_raw() takes a runtime PM reference with pm_runtime_get_sync()\nbefore reading the processed pressure or raw temperature, but on the read\nerror path it returns without calling pm_runtime_put_autosuspend(). Each\nfailed read therefore leaks a runtime PM reference and prevents the device\nfrom autosuspending.\n\nDrop the reference before checking the return value so both the success\nand error paths are balanced."
}
],
"lastModified": "2026-08-17T05:17:55.200",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}