Executive brief
A vulnerability in the Linux kernel's Data Access Monitor (DAMON) component could allow a user with administrative privileges to crash the system. By providing invalid monitoring intervals, an attacker can trigger a 'divide-by-zero' error or an out-of-bounds memory access. This results in a kernel panic, leading to a complete system outage and loss of availability.
Technical details
The vulnerability exists in the 'damon_hot_score()' function within 'mm/damon/ops-common.c'. It stems from improper validation of 'sample_interval' and 'aggr_interval' values provided via sysfs. Specifically, setting the sampling interval to zero triggers a divide-by-zero in 'damon_max_nr_accesses()'. Additionally, extremely high aggregation intervals can cause 'damon_hot_score()' to return a value exceeding 'DAMOS_MAX_SCORE', leading to an out-of-bounds access in the 'regions_score_histogram' array. An attacker with sysfs write permissions can exploit these flaws to trigger a kernel 'Oops' and crash the system. Patches have been released for various stable kernel branches to explicitly handle zero intervals and enforce bounds on the hotness score.
Affected products
- Linux Linux Kernel 5.16.x to 6.x
Timeline
- 2026-06-23: disclosed: Initial discovery and patch submission by SeongJae Park
- 2026-07-01: patched: Mainline kernel patch committed
- 2026-07-25: advisory: CVE-2026-64458 published
References
- https://git.kernel.org/stable/c/35d4a3cf70a855b50e53189ac2f8463e20a02046
- https://git.kernel.org/stable/c/58321b4e6e4f0f412069ab27ccdd56292757343a
- https://git.kernel.org/stable/c/74fef68d521150281e36cdaa20e9e1ee3e3aa146
- https://git.kernel.org/stable/c/76e415ea88d20f022ed5cfcf78c50e156a267e91
- https://git.kernel.org/stable/c/9c8f31eaae6140ecadec0c07320498a944556de2
- https://git.kernel.org/stable/c/ef2ae10a4582bc92b7e944181bbd2f87f3d30f3a