Answer in brief
CVE-2026-90249 records a Unknown severity vulnerability in iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=97d642e23037c5545266f9564c9b81e6db81b122 <b2d7a97d75b648a643f60d77f4d6d70161268855 || >=97d642e23037c5545266f9564c9b81e6db81b122 <685d9d1e5c47e024413981fb7eddab86132b04a1 || >=97d642e23037c5545266f9564c9b81e6db81b122 <56fe8e5f313a64e458bb6f8b982de925345e21a7 || >=97d642e23037c5545266f9564c9b81e6db81b122 <8e76ab81319858736ccf23141e9415f9a1869337 || >=97d642e23037c5545266f9564c9b81e6db81b122 <70b9482926ca92862460e659f5e5fde99ae0b4fa || >=97d642e23037c5545266f9564c9b81e6db81b122 <0fc740c25c9abb25113398ebb58e2f2ce57741a7 || >=97d642e23037c5545266f9564c9b81e6db81b122 <470edb012b1d9a4fba1cd59e329e60f0798c791a || >=97d642e23037c5545266f9564c9b81e6db81b122 <579c049b4cb6fc72ce2c505fc5334540be0efcd3 | b2d7a97d75b648a643f60d77f4d6d70161268855, 685d9d1e5c47e024413981fb7eddab86132b04a1, 56fe8e5f313a64e458bb6f8b982de925345e21a7, 8e76ab81319858736ccf23141e9415f9a1869337, 70b9482926ca92862460e659f5e5fde99ae0b4fa, 0fc740c25c9abb25113398ebb58e2f2ce57741a7, 470edb012b1d9a4fba1cd59e329e60f0798c791a, 579c049b4cb6fc72ce2c505fc5334540be0efcd3 |
| Linux/Linuxgeneric | 5.7 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes The IIO core does not filter duplicate writes to the event enable attribute, so writing the same value twice invokes write_event_config() twice. Enabling twice leaks a runtime PM reference, preventing the device from ever suspending again; disabling twice underflows the usage count and triggers a "Runtime PM usage count underflow" warning. Bail out early when the requested state matches the current state. While at it, switch to pm_runtime_resume_and_get() so a failed resume is propagated to userspace instead of silently marking the event enabled.
Quoted source text, attributed separately from HOL analysis.