Junglewise Threat Intelligence

CVE-2026-43388: Linux Kernel use-after-free in DAMON damos_walk

CVE-2026-43388 · Severity: high · CVSS 7.8 · Published 2026-05-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's memory monitoring component (DAMON) could allow a local user to cause system instability. The issue occurs when the system fails to properly clean up internal references after a specific memory operation is requested while the monitoring service is inactive. This can lead to a 'use-after-free' condition or cause subsequent requests to fail unexpectedly, potentially impacting system availability or allowing for unauthorized memory access.

Technical details

A use-after-free (UAF) vulnerability exists in mm/damon/core.c within the Linux kernel. The function damos_walk() assigns a caller-provided, stack-allocated 'walk_control' structure to the 'damon_ctx' object before verifying if the context is active. If the context is inactive, the function returns -EINVAL without nullifying the pointer, leaving a dangling reference to the now-freed stack memory. A local attacker could potentially exploit this if the context is later started, leading to a kdamond dereference of the stale pointer. Additionally, the stale pointer causes subsequent valid calls to damos_walk() to fail with -EBUSY. The issue has been patched by ensuring the pointer is cleared under the walk_control_lock before returning an error.

Affected products

  • Linux Linux Kernel 6.14 to 6.18.19, 6.19 to 6.19.9, 7.0-rc1 to 7.0-rc3

Timeline

  • 2026-02-23: other: Vulnerability fixed in source code
  • 2026-05-08: disclosed: CVE-2026-43388 published
  • 2026-05-26: advisory: NIST/NVD analysis completed

References

Related threats