CVE-2026-64147: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: pds_core: fix debugfs_lookup dentry leak and error handling debugfs_lookup() returns a dentry with an elevated reference count that must be released with dput(). The current code discards the returned dentry without calling dput(), causing a reference leak on every firmware reset recovery. Additionally, when CONFIG_DEBUG_FS is disabled, debugfs_lookup() returns ERR_PTR(-ENODEV), not NULL. The current check passes for error pointers and would call dput() on an invalid pointer, causing a crash.

Affected products

  • Linux Linux Kernel: from 6.6.16, before 6.6.142 (fixed in 6.6.142); from 6.7.4, before 6.8 (fixed in 6.8); from 6.8.1, before 6.12.92 (fixed in 6.12.92); from 6.13, before 6.18.34 (fixed in 6.18.34); from 6.19, before 7.0.11 (fixed in 7.0.11); version 6.8 only; …

Published 2026-07-19. Last modified 2026-08-17.