Executive brief
The Linux kernel's DAMON memory monitoring module can crash with a division-by-zero error when users configure certain parameters with zero values. An attacker with local access to kernel module parameters could trigger this crash, causing a kernel panic and service outage on the affected system.
Technical details
The vulnerability is a division-by-zero flaw in the damos_quota_score() function within the DAMON (Data Access Monitoring) subsystem. The DAMON_SAMPLE_MTIER sample module allows users to set the node0_mem_free_bp or node0_mem_used_bp kernel module parameters to zero via /sys/module/damon_sample_mtier/parameters. When DAMON is enabled with these zero values, damos_quota_score() attempts to divide by the zero target_value, triggering a kernel oops/panic. The fix involves adding parameter validation to reject zero values for node0_mem_free_bp and node0_mem_used_bp when DAMON is enabled. Attack requires local access to sysfs module parameters; no authentication bypass or network exploitation is possible.
Affected products
- Linux Linux kernel
Timeline
- 2026-08-22: disclosed