Junglewise Threat Intelligence

CVE-2026-72177: Linux kernel DAMON sysfs-schemes memory error handling

CVE-2026-72177 · Severity: info · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's DAMON (Data Access Monitoring) subsystem has an error handling defect in its sysfs-schemes module that can lead to memory corruption. When memory allocation fails during directory setup, the code attempts to release uninitialized memory pointers, potentially causing system crashes or data corruption. This affects systems using kernel-space data access monitoring features.

Technical details

The vulnerability exists in the error handling path of the damon_sysfs_access_pattern_add_dirs() function in mm/damon/sysfs.c. When memory allocation fails in the setup functions for directory objects (sz, nr_accesses, age), the error path attempts to release kobject references in the wrong order. If an allocation fails early, uninitialized memory pointers are dereferenced via kobject_put(), causing uninitialized memory dereference. The fix reorders the error handling labels so that only successfully allocated objects are released. This is a local kernel issue accessible only to code running in kernel space or through privileged sysfs operations.

Affected products

  • Linux Linux kernel 5.18.x and later

Timeline

  • 2026-08-15: disclosed
  • 2026-07-24: patched

References

Related threats