Executive brief
A vulnerability in the Linux kernel's memory monitoring subsystem (DAMON) could allow a local user with administrative privileges to crash the system. By providing an invalid memory node identifier when setting performance goals, an attacker can trigger an out-of-bounds memory access. This results in a kernel panic or system instability, impacting the availability of the server.
Technical details
An out-of-bounds memory access vulnerability exists in mm/damon/core.c within the Linux kernel. The DAMON (Data Access MONitor) subsystem fails to validate the 'nid' (node ID) field in the 'damos_quota_goal' structure when processing 'node_memcg_used_bp' or 'node_memcg_free_bp' metrics. An attacker with sufficient privileges to interface with DAMON (e.g., via the 'damo' tool or sysfs) can provide an arbitrary node ID, which is subsequently used as an index for the NODE_DATA() macro without bounds checking. This leads to a kernel paging request failure and system crash. The issue has been addressed by adding validation via the 'invalid_mem_node()' check.
Affected products
- Linux Linux Kernel 6.19.x and later
Timeline
- 2026-03-28: other: Patch authored by SeongJae Park
- 2026-05-27: advisory: NVD publication date