Executive brief
A vulnerability in the Linux kernel's Data Access Monitoring (DAMON) component could allow a privileged user to crash the system. The component, which helps manage system memory efficiency, fails to properly check memory node identifiers provided by the user. An attacker with administrative privileges could exploit this to cause a kernel crash, leading to a full system service outage.
Technical details
A vulnerability exists in mm/damon/core.c within the Linux kernel due to missing validation of the 'nid' (node ID) field in 'damos_quota_goal'. When users configure DAMOS quota goals via DAMON_SYSFS, the provided node ID is passed directly to 'si_meminfo_node()' and 'NODE_DATA()' macros. An attacker with sufficient privileges to access DAMON_SYSFS can provide an arbitrary or invalid node ID (e.g., -1), triggering an out-of-bounds access or a NULL pointer dereference. This results in a kernel panic and denial of service. The fix introduces 'invalid_mem_node()' to validate that the node ID is within the range of 0 to MAX_NUMNODES and is in a valid memory state.
Affected products
- Linux Linux Kernel 6.16.x and later
Timeline
- 2026-03-28: other: Patch authored by SeongJae Park
- 2026-05-27: disclosed: CVE published