Junglewise Threat Intelligence

CVE-2026-64499: Linux Kernel ti-ads1119 PM reference leak in buffer preenable

CVE-2026-64499 · Severity: info · CVSS 2.1 · Published 2026-07-25

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel driver for the Texas Instruments ADS1119 analog-to-digital converter can lead to a power management reference leak. This issue occurs when a specific hardware communication command fails, causing the device to remain powered on indefinitely. While this does not directly expose data, it can lead to increased power consumption and potential system instability or resource exhaustion over time.

Technical details

A vulnerability exists in the 'ti-ads1119' driver within the Linux kernel's Industrial I/O (IIO) subsystem. The function 'ads1119_triggered_buffer_preenable' calls 'pm_runtime_resume_and_get' to wake the device, but fails to decrement the runtime PM usage counter if a subsequent 'i2c_smbus_write_byte' operation fails. Because the 'postdisable' callback is not triggered upon a 'preenable' failure, the reference count remains elevated, preventing the device from entering a low-power state. This is a local resource management issue that can be exploited if an attacker can trigger repeated I2C communication failures. Patches have been released for various stable kernel branches including 6.12.y and 6.18.y.

Affected products

  • Linux Linux 6.11, 6.12.96, 6.18.39, 7.1.4

Timeline

  • 2026-07-25: disclosed
  • 2026-07-25: advisory

References