« Volver al listado

CVE-2026-46121

Estado: En análisisAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock

Patch series "mm/damon/sysfs-schemes: fix use-after-free for [memcg_]path".

Reads of 'memcg_path' and 'path' files in DAMON sysfs interface could race with their writes, results in use-after-free. Fix those.

This patch (of 2):

damon_sysfs_scheme_filter->mmecg_path can be read and written by users, via DAMON sysfs memcg_path file. It can also be indirectly read, for the parameters {on,off}line committing to DAMON.

Leer descripción completaMostrar menos

The reads for parameters committing are protected by damon_sysfs_lock to avoid the sysfs files being destroyed while any of the parameters are being read. But the user-driven direct reads and writes are not protected by any lock, while the write is deallocating the memcg_path-pointing buffer. As a result, the readers could read the already freed buffer (user-after-free). Note that the user-reads don't race when the same open file is used by the writer, due to kernfs's open file locking. Nonetheless, doing the reads and writes with separate open files would be common. Fix it by protecting both the user-direct reads and writes with damon_sysfs_lock.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local (AV:L/PR:L) de use-after-free en kernel Linux que permite escalada de privilegios mediante lectura/escritura de memoria. Ejecución de código o denegación de servicio posibles al acceder a buffer liberado.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-46121",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "490a43d07f1663d827e802720d30cbc0494e4f81",
              "lessThan": "b1e9f2d5870776347edef927f9bb3ea19b8e3abb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c5d5b0047b0c0f304608f3824139f7bd34c48413",
              "lessThan": "c88802d0e8edd14b6cd2daf3000f99adbc4c85c5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4f489fe6afb395dbc79840efa3c05440b760d883",
              "lessThan": "eafd6f5372d29b0dd213799b92c2c9c7ad31d7da",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4f489fe6afb395dbc79840efa3c05440b760d883",
              "lessThan": "baecc45ad60e621ef14d6c1e7f41ef36bbfdf910",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4f489fe6afb395dbc79840efa3c05440b760d883",
              "lessThan": "1e68eb96e8beb1abefd12dd22c5637795d8a877e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4a158ac0538dd5695eeaa00aa0720d711f3e4ef1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.6.96",
              "lessThan": "6.6.140",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.36",
              "lessThan": "6.12.88",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.15.5",
              "lessThan": "6.16",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "mm/damon/sysfs-schemes.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.16"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.16",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.140",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.88",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.30",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.0.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.0.*"
            },
            {
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "mm/damon/sysfs-schemes.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-05-28T10:16:27.600",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1e68eb96e8beb1abefd12dd22c5637795d8a877e",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b1e9f2d5870776347edef927f9bb3ea19b8e3abb",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/baecc45ad60e621ef14d6c1e7f41ef36bbfdf910",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c88802d0e8edd14b6cd2daf3000f99adbc4c85c5",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/eafd6f5372d29b0dd213799b92c2c9c7ad31d7da",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-416"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock\n\nPatch series \"mm/damon/sysfs-schemes: fix use-after-free for [memcg_]path\".\n\nReads of 'memcg_path' and 'path' files in DAMON sysfs interface could race\nwith their writes, results in use-after-free.  Fix those.\n\n\nThis patch (of 2):\n\ndamon_sysfs_scheme_filter->mmecg_path can be read and written by users,\nvia DAMON sysfs memcg_path file.  It can also be indirectly read, for the\nparameters {on,off}line committing to DAMON.  The reads for parameters\ncommitting are protected by damon_sysfs_lock to avoid the sysfs files\nbeing destroyed while any of the parameters are being read.  But the\nuser-driven direct reads and writes are not protected by any lock, while\nthe write is deallocating the memcg_path-pointing buffer.  As a result,\nthe readers could read the already freed buffer (user-after-free).  Note\nthat the user-reads don't race when the same open file is used by the\nwriter, due to kernfs's open file locking.  Nonetheless, doing the reads\nand writes with separate open files would be common.  Fix it by protecting\nboth the user-direct reads and writes with damon_sysfs_lock."
    }
  ],
  "lastModified": "2026-06-24T16:51:34.720",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6F59F59B-0B5E-4FDE-9C04-14918F1FC132",
              "versionEndExcluding": "6.6.140",
              "versionStartIncluding": "6.6.96"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5BDE39B7-94D9-46FE-800D-F242F5EF34BD",
              "versionEndExcluding": "6.12.88",
              "versionStartIncluding": "6.12.36"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D10C9120-0117-4346-95CC-E5D06B9133C4",
              "versionEndExcluding": "6.16",
              "versionStartIncluding": "6.15.5"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A544F5E4-2BCE-4FFA-98B2-08E08A05FF7E",
              "versionEndExcluding": "6.18.30",
              "versionStartIncluding": "6.16.1"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0893CA7-9AE6-4DFE-AC75-48967D73AD8E",
              "versionEndExcluding": "7.0.7",
              "versionStartIncluding": "6.19"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.16:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6238B17D-C12B-458F-A138-97039BFC4595"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0517869-312D-4429-80C2-561086E1421C"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85421F4E-C863-4ABF-B4B4-E887CC2F7F92"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3827F0D4-5FEE-4181-B267-5A45E7CA11FC"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A9C2DE5-43B8-4D73-BDB5-EA55C7671A52"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B1EF7059-E670-45F4-B422-54C40FA86390"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}