CVE-2026-64022

Source
https://cve.org/CVERecord?id=CVE-2026-64022
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64022.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64022
Downstream
Published
2026-07-19T15:39:15.345Z
Modified
2026-07-21T03:47:48.423781805Z
Summary
gpio: aggregator: remove the software node when deactivating the aggregator
Details

In the Linux kernel, the following vulnerability has been resolved:

gpio: aggregator: remove the software node when deactivating the aggregator

The dynamic software node we create for the aggregator platform device when using configfs is leaked when the device is deactivated. Destroy it as the last step in the tear-down path.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64022.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
86f162e73d2d81ef6d819c06a3b6c2fda77a79b8
Fixed
3e657619cf7258cb53b1beaf0d02998297695cde
Fixed
9870ea9a4a25abef3e7af3445bfce2472528a546
Fixed
61fef83f239ecace1cce716135762a2d9b7b1fc6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64022.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.16.0
Fixed
6.18.34
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.11

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64022.json"