Junglewise Threat Intelligence

CVE-2026-74645: Linux kernel DAMON LRU sort division by zero in quota scoring

CVE-2026-74645 · Severity: info · CVSS 5.5 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

DAMON LRU sort is a Linux kernel memory management feature that optimizes memory usage by managing hot and cold data. A misconfiguration of the active_mem_bp parameter can trigger a division by zero error that causes a kernel panic, denying service to the affected system. This requires privileged module parameter write access to exploit.

Technical details

The vulnerability is a divide-by-zero error in the damos_quota_score() function within the DAMON LRU sort module. When the active_mem_bp parameter is set to a value greater than 10000, the calculation '10000 - active_mem_bp + 2' for the cold memory scheme's quota goal can result in zero or a negative value that becomes zero, causing division by zero. The vulnerability requires local access with module parameter write permissions to /sys/module/damon_lru_sort/parameters. The fix validates that active_mem_bp does not exceed 10000 and returns an error if it does, preventing the kernel panic.

Affected products

  • Linux Linux Kernel 7.0.x and later (including 5.10, 5.15, 6.1, 6.6, and other stable series)

Timeline

  • 2026-08-22: disclosed: CVE-2026-74645 published
  • 2026-08-04: patched: Fix committed to Linux kernel stable tree (commit 06befa61c427e74319781e6f35a364cfc32dbae8)

References

Related threats