Junglewise Threat Intelligence

CVE-2026-43355: Linux Kernel bh1780 light sensor PM runtime leak

CVE-2026-43355 · Severity: medium · CVSS 5.5 · Published 2026-05-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's driver for the ROHM BH1780 light sensor. An error in how the system manages power for this sensor could lead to a resource leak, potentially causing system instability or preventing the hardware from entering power-saving modes correctly. This issue primarily affects systems using this specific light sensor hardware.

Technical details

A resource leak (CWE-401) exists in drivers/iio/light/bh1780.c within the bh1780_read_raw function. The driver calls pm_runtime_get_sync() to increment the power management reference count but fails to call pm_runtime_put_autosuspend() if the subsequent bh1780_read_word operation returns an error. This results in a permanent increment of the reference count, preventing the device from ever entering a low-power state. An attacker with local access could potentially trigger this error path repeatedly to exhaust resources or impact system power management. The fix involves reordering the code to ensure the reference count is decremented regardless of the read operation's success.

Affected products

  • Linux Linux Kernel 4.7 to 5.10.253, 6.1.167, 6.6.130, 6.18.19, 6.19.9

Timeline

  • 2026-05-08: advisory: NVD publication date
  • 2026-03-19: patched: Initial patch authored

References

Related threats