PT-2026-64591 · Linux+1 · Linux Kernel+1

CVE-2026-64370

·

Published

2026-07-25

·

Updated

2026-09-07

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A pid refcount leak occurs in the do cpu nanosleep() function. The posix cpu timer create() function acquires a pid reference using get pid() and stores it in timer.it.cpu.pid. If the following posix cpu timer set() call fails, the function returns without executing posix cpu timer del(), which fails to release the pid reference and results in a leak.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-93861
CVE-2026-64370
ECHO-D7F7-A21E-EA97
OPENSUSE-SU-2026:11476-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu