In the Linux kernel, the following vulnerability has been resolved:
mm/damon/core: fix new damon_target objects leaks on damon_commit_targets()
Patch series "mm/damon/core: fix memory leaks and ignored inputs from damon_commit_ctx()".
Due to two bugs in damon_commit_targets() and damon_commit_schemes(), which are called from damon_commit_ctx(), some user inputs can be ignored, and some mmeory objects can be leaked. Fix those.
Note that only DAMON sysfs interface users are affected. Other DAMON core API user modules that more focused more on simple and dedicated production usages, including DAMON_RECLAIM and DAMON_LRU_SORT are not using the buggy function in the way, so not affected.
This patch (of 2):
When new DAMON targets are added via damon_commit_targets(), the newly created targets are not deallocated when updating the internal data (damon_commit_target()) is failed. Worse yet, even if the setup is successfully done, the new target is not linked to the context. Hence, the new targets are always leaked regardless of the internal data setup failure. Fix the leaks.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Ubuntu | — | Upgrade linux-image-realtime-hwe-24.04Upgrade linux-image-lowlatencyUpgrade linux-image-raspiUpgrade linux-image-6.11.0-1013-oracleUpgrade linux-image-6.11.0-1011-lowlatency-64kUpgrade linux-image-lowlatency-hwe-24.04Upgrade linux-image-azure-fdeUpgrade linux-image-lowlatency-64k-hwe-24.04Upgrade linux-image-virtual-hwe-24.04Upgrade linux-image-6.11.0-1011-awsUpgrade linux-image-generic-64kUpgrade linux-image-6.11.0-1012-azureUpgrade linux-image-6.11.0-1007-realtimeUpgrade linux-image-genericUpgrade linux-image-oem-24.04bUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-lowlatency-64kUpgrade linux-image-virtualUpgrade linux-image-oracle-64kUpgrade linux-image-6.11.0-21-genericUpgrade linux-image-azureUpgrade linux-image-6.11.0-1011-gcp-64kUpgrade linux-image-oem-24.04aUpgrade linux-image-gcpUpgrade linux-image-6.11.0-1012-azure-fdeUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-oracleUpgrade linux-image-6.11.0-1011-lowlatencyUpgrade linux-image-6.11.0-1011-gcpUpgrade linux-image-oem-24.04Upgrade linux-image-6.11.0-1017-oemUpgrade linux-image-awsUpgrade linux-image-6.11.0-21-generic-64kUpgrade linux-image-6.11.0-1010-raspiUpgrade linux-image-gcp-64kUpgrade linux-image-realtimeUpgrade linux-image-6.11.0-1013-oracle-64k | Mar 28, 2025 | Jan 15, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub