Junglewise Threat Intelligence

CVE-2026-64185: Linux Kernel sysfs directory deletion on update failure

CVE-2026-64185 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's sysfs component, which is responsible for managing system information and device drivers. Under specific low-memory conditions, the system could accidentally delete existing configuration directories when trying to update them. This could lead to unexpected system behavior or the loss of access to certain hardware settings until the system is rebooted or the configuration is manually restored.

Technical details

A logic error exists in the Linux kernel's sysfs implementation within `fs/sysfs/group.c`. When `sysfs_update_group()` is called for a named group and an internal file creation fails (e.g., due to an -ENOMEM error), `internal_create_group()` incorrectly calls `kernfs_remove()` on the directory. Because the directory already existed prior to the update attempt, this results in the silent destruction of a sysfs group that the caller did not create. The fix ensures that the directory is only removed if it was newly created during the current operation. This issue affects various stable branches and has been patched in multiple kernel versions.

Affected products

  • Linux Linux Kernel 4.19 to 6.9.x

Timeline

  • 2026-05-20: patched: Initial fix authored by Greg Kroah-Hartman
  • 2026-07-19: disclosed: CVE published and NVD record created

References

Related threats