CVE-2026-72176
In the Linux kernel, the following vulnerability has been resolved:
mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error
damon_sysfs_scheme_add_dirs() setup the tried_regions directory after the stats directory setup is completed. When the tried_regions directory setup is failed, the setup function ensures the reference for the tried regions directory is released. Hence the error path should put references on setup succeeded directory objects, starting from the stats directory. However, the error path is putting the tried_regions directory instead of the stats directory.
As a direct result, the stats directory object is leaked. Worse yet, if the tried_regions directory setup failed from the initial allocation, the scheme->tried_regions field remains uninitialized.
Leer descripción completaMostrar menos
The following kobject_put(&scheme->tried_regions->kobj) call in the error path will dereference the uninitialized memory. The setup failures should not be common. But once it happens, the consequence is quite bad.
Fix this issue by correctly putting the stats directory instead of the tried_regions directory.
The issue was discovered [1] by Sashiko.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/05ea83ee88ca70f8932906d9f2617ff996f45b50
- https://git.kernel.org/stable/c/40a04601a3f66cabd6629c258a07af645a658865
- https://git.kernel.org/stable/c/50a753171d255895e5dd41566986b48dcec06f31
- https://git.kernel.org/stable/c/6b6b5d7c2c957136b92c00b77b7175259f13082b
- https://git.kernel.org/stable/c/f63d6e5ba72aeacdee4fddc902bd7616cd62b919
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-72176",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5181b75f438d2e5b7f27bf48c6ea88a87c2882b7",
"lessThan": "50a753171d255895e5dd41566986b48dcec06f31",
"versionType": "git"
},
{
"status": "affected",
"version": "5181b75f438d2e5b7f27bf48c6ea88a87c2882b7",
"lessThan": "f63d6e5ba72aeacdee4fddc902bd7616cd62b919",
"versionType": "git"
},
{
"status": "affected",
"version": "5181b75f438d2e5b7f27bf48c6ea88a87c2882b7",
"lessThan": "40a04601a3f66cabd6629c258a07af645a658865",
"versionType": "git"
},
{
"status": "affected",
"version": "5181b75f438d2e5b7f27bf48c6ea88a87c2882b7",
"lessThan": "6b6b5d7c2c957136b92c00b77b7175259f13082b",
"versionType": "git"
},
{
"status": "affected",
"version": "5181b75f438d2e5b7f27bf48c6ea88a87c2882b7",
"lessThan": "05ea83ee88ca70f8932906d9f2617ff996f45b50",
"versionType": "git"
}
],
"programFiles": [
"mm/damon/sysfs-schemes.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.2"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.2",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"mm/damon/sysfs-schemes.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:21:35.810",
"references": [
{
"url": "https://git.kernel.org/stable/c/05ea83ee88ca70f8932906d9f2617ff996f45b50",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/40a04601a3f66cabd6629c258a07af645a658865",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/50a753171d255895e5dd41566986b48dcec06f31",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6b6b5d7c2c957136b92c00b77b7175259f13082b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f63d6e5ba72aeacdee4fddc902bd7616cd62b919",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error\n\ndamon_sysfs_scheme_add_dirs() setup the tried_regions directory after the\nstats directory setup is completed. When the tried_regions directory\nsetup is failed, the setup function ensures the reference for the tried\nregions directory is released. Hence the error path should put references\non setup succeeded directory objects, starting from the stats directory. \nHowever, the error path is putting the tried_regions directory instead of\nthe stats directory.\n\nAs a direct result, the stats directory object is leaked. Worse yet, if\nthe tried_regions directory setup failed from the initial allocation, the\nscheme->tried_regions field remains uninitialized. The following\nkobject_put(&scheme->tried_regions->kobj) call in the error path will\ndereference the uninitialized memory. The setup failures should not be\ncommon. But once it happens, the consequence is quite bad.\n\nFix this issue by correctly putting the stats directory instead of the\ntried_regions directory.\n\nThe issue was discovered [1] by Sashiko."
}
],
"lastModified": "2026-08-17T06:18:18.120",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}