Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64370

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/07/2026
Última modificación:
25/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path<br /> <br /> In do_cpu_nanosleep(), posix_cpu_timer_create() takes a pid reference<br /> via get_pid() and stores it in timer.it.cpu.pid. If the subsequent<br /> posix_cpu_timer_set() call fails, the function returns immediately<br /> without calling posix_cpu_timer_del() to release the pid reference,<br /> causing a leak.<br /> <br /> Fix it by calling posix_cpu_timer_del() before the unlock-and-return<br /> on the error path, consistent with the other exit paths in the same<br /> function.

Impacto