---
cve: "CVE-2026-64147"
severity: "LOW"
cvss: 3.1
epss: "0.1%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-07-19 16:17:56"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-24T21:00:38+02:00"
---

# CVE-2026-64147

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

pds_core: fix debugfs_lookup dentry leak and error handling

debugfs_lookup() returns a dentry with an elevated reference count that
must be released with dput(). The current code discards the returned
dentry without calling dput(), causing a reference leak on every
firmware reset recovery.

Additionally, when CONFIG_DEBUG_FS is disabled, debugfs_lookup()
returns ERR_PTR(-ENODEV), not NULL. The current check passes for error
pointers and would call dput() on an invalid pointer, causing a crash.

## Patch verfügbar (OSV)

- Kernel ≥ 6.6.142
- Kernel ≥ 6.12.92
- Kernel ≥ 6.18.34
- Kernel ≥ 7.0.11

## Referenzen

- <https://git.kernel.org/stable/c/60ef1675b652e912f3eb064767af4432393291fd>
- <https://git.kernel.org/stable/c/26e19622c485e53c3fdb299e822068a0542ddf0c>
- <https://git.kernel.org/stable/c/91d13e92b983e6c6d7631012c2e20ae8057de9f2>
- <https://git.kernel.org/stable/c/d7f4dd4c8fb380898fef7a77d48fce7ccdb4fc32>
- <https://git.kernel.org/stable/c/dc416e32baaeb620b9809e9e25fc7b30889686e9>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-64147) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
