CVE-2026-64493

UnknownEPSS 0.17%

Last modified

CVE-2026-64493 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: iio: pressure: mpl115: fix runtime PM leak on read error mpl115_read_raw() takes a runtime PM reference with pm_runtime_get_sync() before reading the processed pressure or raw temperature, but on the read error path it returns without calling pm_runtime_put_autosuspend(). Each failed read therefore leaks a runtime PM reference and prevents the device from autosuspending. Drop the reference before checking the return value so both the success and error paths are balanced.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: iio: pressure: mpl115: fix runtime PM leak on read error mpl115_read_raw() takes a runtime PM reference with pm_runtime_get_sync() before reading the processed pressure or raw temperature, but on the read error path it returns without calling pm_runtime_put_autosuspend(). Each failed read therefore leaks a runtime PM reference and prevents the device from autosuspending. Drop the reference before checking the return value so both the success and error paths are balanced.

Metrics

EPSS Probability
0.17%

6.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a, < 5022f4ed5aae974ec530e3cbf0bd223be13055f7; >= 0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a, < aab0fed636b14a5fd52fcae58b484f1cb96b841d; >= 0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a, < b3f1af4ba8e9cf33aa08c4cdcaa5a17b140521ec; >= 0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a, < 46e69d3dd429b33e50e2731913239f6af4ea2705; >= 0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a, < fbe67ff37a6fd855a6c097f84f3738bd13d0a898
LinuxLinux6.2

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-64493?
In the Linux kernel, the following vulnerability has been resolved: iio: pressure: mpl115: fix runtime PM leak on read error mpl115_read_raw() takes a runtime PM reference with pm_runtime_get_sync() before reading the processed pressure or raw temperature, but on the read error path it returns without calling pm_runtime_put_autosuspend(). Each failed read therefore leaks a runtime PM reference and prevents the device from autosuspending. Drop the reference before checking the return value so both the success and error paths are balanced.
How severe is CVE-2026-64493?
Severity scoring for CVE-2026-64493 is pending analysis. The EPSS model estimates a 0.17% probability of exploitation in the next 30 days.
How do I fix CVE-2026-64493?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-64493?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST