Junglewise Threat Intelligence

CVE-2026-64503: Linux Kernel KXSD9 accelerometer power management imbalance in write_raw

CVE-2026-64503 · Severity: info · CVSS 2.1 · Published 2026-07-25

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's driver for the KXSD9 accelerometer can prevent the device from entering power-saving modes. By sending specific invalid commands to the sensor, the system's power management counter becomes corrupted, leading to increased power consumption and potential battery drain. This issue primarily affects hardware using this specific sensor and does not risk data loss or unauthorized access.

Technical details

A reference counting error (runtime PM imbalance) exists in the kxsd9_write_raw() function within drivers/iio/accel/kxsd9.c. The function acquires a power management reference using pm_runtime_get_sync() but fails to release it via pm_runtime_put_autosuspend() when returning an -EINVAL error for scales with non-zero integer parts. This results in a permanent increment of the device's usage counter, preventing the hardware from entering autosuspend states. An attacker with local access to the IIO device interface could repeatedly trigger this error to cause a minor denial of service regarding power management efficiency. The issue has been resolved by ensuring the error path falls through to the proper cleanup routine.

Affected products

  • Linux Linux 4.9 to 6.1.178

Timeline

  • 2026-07-25: disclosed: CVE published by kernel.org and NVD
  • 2026-07-18: patched: Fix committed to stable kernel branches

References