Junglewise Threat Intelligence

CVE-2026-74643: Linux kernel DAMON division by zero in damos_quota_score

CVE-2026-74643 · Severity: info · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's DAMON memory monitoring module can crash with a division-by-zero error when users configure certain parameters with zero values. An attacker with local access to kernel module parameters could trigger this crash, causing a kernel panic and service outage on the affected system.

Technical details

The vulnerability is a division-by-zero flaw in the damos_quota_score() function within the DAMON (Data Access Monitoring) subsystem. The DAMON_SAMPLE_MTIER sample module allows users to set the node0_mem_free_bp or node0_mem_used_bp kernel module parameters to zero via /sys/module/damon_sample_mtier/parameters. When DAMON is enabled with these zero values, damos_quota_score() attempts to divide by the zero target_value, triggering a kernel oops/panic. The fix involves adding parameter validation to reject zero values for node0_mem_free_bp and node0_mem_used_bp when DAMON is enabled. Attack requires local access to sysfs module parameters; no authentication bypass or network exploitation is possible.

Affected products

  • Linux Linux kernel

Timeline

  • 2026-08-22: disclosed

Related threats