Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
CVE-2026-64185: Linux Kernel: sysfs Directory Deletion Failure
CVE-2026-64185
CVE-2026-64185
Summary
A bug in the Linux kernel's sysfs file system could cause it to delete a directory when updating fails. This can result in the loss of sysfs group data. To fix this issue, ensure you update your Linux kernel to the latest version.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| linux | linux |
< c5e125c828b701afaf7493b42a14aa89362ff36d 4.19 |
Original title
In the Linux kernel, the following vulnerability has been resolved:
sysfs: don't remove existing directory on update failure
When sysfs_update_group() is called for a named group and create_files...
Original description
In the Linux kernel, the following vulnerability has been resolved:
sysfs: don't remove existing directory on update failure
When sysfs_update_group() is called for a named group and create_files()
fails (e.g. -ENOMEM), internal_create_group() calls kernfs_remove(kn) on
the group directory. In the update path, kn was obtained via
kernfs_find_and_get() and refers to a directory that already existed
before this call. Removing it silently destroys a sysfs group that the
caller did not create.
Only remove the directory if we created it ourselves. On update failure
the directory remains as it is left empty by remove_files() inside
create_files(), but can be repopulated by a retry.
sysfs: don't remove existing directory on update failure
When sysfs_update_group() is called for a named group and create_files()
fails (e.g. -ENOMEM), internal_create_group() calls kernfs_remove(kn) on
the group directory. In the update path, kn was obtained via
kernfs_find_and_get() and refers to a directory that already existed
before this call. Removing it silently destroys a sysfs group that the
caller did not create.
Only remove the directory if we created it ourselves. On update failure
the directory remains as it is left empty by remove_files() inside
create_files(), but can be repopulated by a retry.
- https://git.kernel.org/stable/c/c5e125c828b701afaf7493b42a14aa89362ff36d
- https://git.kernel.org/stable/c/ccadd32cc1263802a5969c9efe0e96225450428c
- https://git.kernel.org/stable/c/14f2c14ae86c4af17a0a9f8ab46dacf2d5fd1d8a
- https://git.kernel.org/stable/c/31527d80234caf83dc96ad478645e57df9de4472
- https://git.kernel.org/stable/c/57b285e0368290aa55f79ba11419b96d0ebdb418
- https://git.kernel.org/stable/c/48fa96538bd2868034d33429e4565fda384d0736
- https://git.kernel.org/stable/c/708f6926f61f71e09b5e9fd668b9882ccd46e69f
- https://git.kernel.org/stable/c/237557b8a81ab948e8332f7c0058e758f081c0a3
Published: 19 Jul 2026 · Updated: 19 Jul 2026 · First seen: 19 Jul 2026