HomeDefectsLIN1025-17215
Acknowledged

LIN1025-17215 : Security Advisory - linux - CVE-2026-64185

Created: Aug 1, 2026    Updated: Aug 11, 2026
Found In Version: 10.25.33.2
Severity: Standard
Applicable for: Wind River Linux LTS 25
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  sysfs: don't remove existing directory on update failure  When sysfs_update_group() is called for a named group and create_files() fails (e.g. -ENOMEM), internal_create_group() calls kernfs_remove(kn) on the group directory.  In the update path, kn was obtained via kernfs_find_and_get() and refers to a directory that already existed before this call.  Removing it silently destroys a sysfs group that the caller did not create.  Only remove the directory if we created it ourselves.  On update failure the directory remains as it is left empty by remove_files() inside create_files(), but can be repopulated by a retry.