Executive brief
A vulnerability in the Linux kernel's Data Access Monitor (DAMON) component could allow a local attacker to cause a system deadlock or memory leak. DAMON is a subsystem used for monitoring and optimizing memory access patterns. If an exploit occurs, it could lead to a partial system hang or gradual depletion of system memory, potentially impacting the stability and performance of the server.
Technical details
A race condition exists in the Linux kernel's mm/damon/core.c due to improper synchronization between damon_call() and the kdamond termination process. When kdamond_fn() finishes its main loop, it cancels pending requests and unsets damon_ctx->kdamond using different mutexes than those used by damon_call() for request registration. An attacker or a poorly timed system process can trigger a state where damon_call() registers a new request after cancellation has occurred but before the running state is updated, causing the calling thread to wait indefinitely for a response that will never come (deadlock). Additionally, if the request is in repeat mode with dealloc_on_cancel, memory may be leaked. The fix introduces a 'call_controls_obsolete' field protected by the call_controls_lock to ensure atomic registration checks.
Affected products
- Linux Linux Kernel 6.14.x and earlier
Timeline
- 2026-03-27: patched: Initial patch submitted by SeongJae Park
- 2026-05-27: disclosed: CVE-2026-46025 published