CVE-2026-97407: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ASoC: rockchip: rockchip_pdm: Handle runtime PM resume failures in set_fmt rockchip_pdm_set_fmt() calls pm_runtime_get_sync() before accessing hardware registers, but ignores its return value. If the runtime resume fails, the function continues to perform register accesses while the device state is undefined. Replace pm_runtime_get_sync() with pm_runtime_resume_and_get() and return early on failure to avoid unpowered register accesses.
Affected products
- Linux Linux: from 4.14.118, before 4.15 (fixed in 4.15); from 4.19.42, before 4.20 (fixed in 4.20); from 5.0.15, before 5.1 (fixed in 5.1); from 5.1, before 5.10.271 (fixed in 5.10.271); from 5.11, before 5.15.222 (fixed in 5.15.222); from 5.16, before 6.1.189 (fixed in 6.1.189); …
Published 2026-09-24. Last modified 2026-10-03.