pds_core: fix debugfs_lookup dentry leak and error handling

Summary

CVECVE-2026-64147
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-07-19 16:17:56 UTC
Updated2026-07-19 16:17:56 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: pds_core: fix debugfs_lookup dentry leak and error handling debugfs_lookup() returns a dentry with an elevated reference count that must be released with dput(). The current code discards the returned dentry without calling dput(), causing a reference leak on every firmware reset recovery. Additionally, when CONFIG_DEBUG_FS is disabled, debugfs_lookup() returns ERR_PTR(-ENODEV), not NULL. The current check passes for error pointers and would call dput() on an invalid pointer, causing a crash.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 2bbf2b1c20f934a054172175ccbabcc01fe69ef6 60ef1675b652e912f3eb064767af4432393291fd git Not specified
CNA Linux Linux affected bc90fbe0c3182157d2be100a2f6c2edbb1820677 26e19622c485e53c3fdb299e822068a0542ddf0c git Not specified
CNA Linux Linux affected bc90fbe0c3182157d2be100a2f6c2edbb1820677 91d13e92b983e6c6d7631012c2e20ae8057de9f2 git Not specified
CNA Linux Linux affected bc90fbe0c3182157d2be100a2f6c2edbb1820677 d7f4dd4c8fb380898fef7a77d48fce7ccdb4fc32 git Not specified
CNA Linux Linux affected bc90fbe0c3182157d2be100a2f6c2edbb1820677 dc416e32baaeb620b9809e9e25fc7b30889686e9 git Not specified
CNA Linux Linux affected 3ffe14c36985e3174933127c9efad82ac8f3fefb git Not specified
CNA Linux Linux affected 6.6.16 6.6.142 semver Not specified
CNA Linux Linux affected 6.7.4 6.8 semver Not specified
CNA Linux Linux affected 6.8 Not specified
CNA Linux Linux unaffected 6.8 semver Not specified
CNA Linux Linux unaffected 6.6.142 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.92 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.34 6.18.* semver Not specified
CNA Linux Linux unaffected 7.0.11 7.0.* semver Not specified
CNA Linux Linux unaffected 7.1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/d7f4dd4c8fb380898fef7a77d48fce7ccdb4fc32 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/60ef1675b652e912f3eb064767af4432393291fd 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/dc416e32baaeb620b9809e9e25fc7b30889686e9 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/91d13e92b983e6c6d7631012c2e20ae8057de9f2 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/26e19622c485e53c3fdb299e822068a0542ddf0c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report