Operation on a Resource after Expiration or Release in Linux kernel - CVE-2026-64185
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in sysfs_update_group() and internal_create_group() when handling updates to a named sysfs group after create_files() fails. A local user can trigger an update operation that causes file creation to fail to cause a denial of service.
The issue affects the update path for an already existing named sysfs group, which may be silently removed instead of left intact.
How to mitigate CVE-2026-64185
Sources
- https://git.kernel.org/stable/c/14f2c14ae86c4af17a0a9f8ab46dacf2d5fd1d8a
- https://git.kernel.org/stable/c/237557b8a81ab948e8332f7c0058e758f081c0a3
- https://git.kernel.org/stable/c/31527d80234caf83dc96ad478645e57df9de4472
- https://git.kernel.org/stable/c/48fa96538bd2868034d33429e4565fda384d0736
- https://git.kernel.org/stable/c/57b285e0368290aa55f79ba11419b96d0ebdb418
- https://git.kernel.org/stable/c/708f6926f61f71e09b5e9fd668b9882ccd46e69f
- https://git.kernel.org/stable/c/c5e125c828b701afaf7493b42a14aa89362ff36d
- https://git.kernel.org/stable/c/ccadd32cc1263802a5969c9efe0e96225450428c