CVE-2026-64370

Published: Lug 25, 2026 Last Modified: Lug 25, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

In the Linux kernel, the following vulnerability has been resolved:

posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path

In do_cpu_nanosleep(), posix_cpu_timer_create() takes a pid reference
via get_pid() and stores it in timer.it.cpu.pid. If the subsequent
posix_cpu_timer_set() call fails, the function returns immediately
without calling posix_cpu_timer_del() to release the pid reference,
causing a leak.

Fix it by calling posix_cpu_timer_del() before the unlock-and-return
on the error path, consistent with the other exit paths in the same
function.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0018
Percentile
0,1th
Updated

Single Data Point

Only one EPSS measurement is available for this CVE. Trend analysis requires multiple data points over time.

https://git.kernel.org/stable/c/7776f9226e99eb49d97492b0b445027cfcb189da
https://git.kernel.org/stable/c/87bd2ad568e15b90d5f7d4bcd70342d05dad649c
https://git.kernel.org/stable/c/8a270b1258797f61b61da44f8bfd41a581b5c85b
https://git.kernel.org/stable/c/8f06363446c5d043c9a7c008b250040e9de98cf9
https://git.kernel.org/stable/c/afed3cdc1cca133f804fcf57ff228974f424b23a
https://git.kernel.org/stable/c/d605d00085adc3fddf67de01dc2a44aebf1a3fb5
https://git.kernel.org/stable/c/e5ffc638faf5dc7d9dc85c9a95e10bf97442e0c0
https://git.kernel.org/stable/c/eb4cec29a78334d09bcfb41c0660cdd62ba05843