Executive brief
A vulnerability was identified in the Linux kernel's Data Access Monitoring (DAMON) subsystem. This component helps manage system memory efficiency. A flaw in how the system handles certain configuration files could allow a local user to trigger a memory error, potentially leading to a system crash or unauthorized access to sensitive kernel information.
Technical details
A use-after-free (UAF) vulnerability exists in mm/damon/sysfs-schemes.c within the Linux kernel. The 'path' file in the DAMON sysfs interface allows users to read and write to damon_sysfs_quot_goal->path. While indirect reads were protected by damon_sysfs_lock, direct user-driven reads (path_show) and writes (path_store) were not. A race condition occurs when one process writes to the path (deallocating the buffer) while another process reads it, leading to a use-after-free. This can be exploited by local users using separate open file descriptors to bypass kernfs's internal locking. The fix implements mutex_trylock using damon_sysfs_lock in both path_show and path_store.
Affected products
- Linux Linux Kernel 6.19.x
Timeline
- 2026-04-23: disclosed: Initial patch submitted by SeongJae Park
- 2026-05-28: advisory: CVE-2026-46183 published in NVD