{"id":"CVE-2026-64185","summary":"sysfs: don't remove existing directory on update failure","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nsysfs: don't remove existing directory on update failure\n\nWhen sysfs_update_group() is called for a named group and create_files()\nfails (e.g. -ENOMEM), internal_create_group() calls kernfs_remove(kn) on\nthe group directory.  In the update path, kn was obtained via\nkernfs_find_and_get() and refers to a directory that already existed\nbefore this call.  Removing it silently destroys a sysfs group that the\ncaller did not create.\n\nOnly remove the directory if we created it ourselves.  On update failure\nthe directory remains as it is left empty by remove_files() inside\ncreate_files(), but can be repopulated by a retry.","modified":"2026-07-21T03:47:54.798300132Z","published":"2026-07-19T15:41:07.340Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64185.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/14f2c14ae86c4af17a0a9f8ab46dacf2d5fd1d8a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/237557b8a81ab948e8332f7c0058e758f081c0a3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/31527d80234caf83dc96ad478645e57df9de4472"},{"type":"WEB","url":"https://git.kernel.org/stable/c/48fa96538bd2868034d33429e4565fda384d0736"},{"type":"WEB","url":"https://git.kernel.org/stable/c/57b285e0368290aa55f79ba11419b96d0ebdb418"},{"type":"WEB","url":"https://git.kernel.org/stable/c/708f6926f61f71e09b5e9fd668b9882ccd46e69f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c5e125c828b701afaf7493b42a14aa89362ff36d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ccadd32cc1263802a5969c9efe0e96225450428c"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64185.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64185"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"c855cf2759d27142f771173d9fd8e7fdf9cf5138"},{"fixed":"c5e125c828b701afaf7493b42a14aa89362ff36d"},{"fixed":"ccadd32cc1263802a5969c9efe0e96225450428c"},{"fixed":"14f2c14ae86c4af17a0a9f8ab46dacf2d5fd1d8a"},{"fixed":"31527d80234caf83dc96ad478645e57df9de4472"},{"fixed":"57b285e0368290aa55f79ba11419b96d0ebdb418"},{"fixed":"48fa96538bd2868034d33429e4565fda384d0736"},{"fixed":"708f6926f61f71e09b5e9fd668b9882ccd46e69f"},{"fixed":"237557b8a81ab948e8332f7c0058e758f081c0a3"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64185.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.19.0"},{"fixed":"5.10.258"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.209"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.175"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.142"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.92"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.34"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.0.11"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64185.json"}}],"schema_version":"1.7.5"}