CVE-2026-46121
In the Linux kernel, the following vulnerability has been resolved:
mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock
Patch series "mm/damon/sysfs-schemes: fix use-after-free for [memcg_]path".
Reads of 'memcg_path' and 'path' files in DAMON sysfs interface could race with their writes, results in use-after-free. Fix those.
This patch (of 2):
damon_sysfs_scheme_filter->mmecg_path can be read and written by users, via DAMON sysfs memcg_path file. It can also be indirectly read, for the parameters {on,off}line committing to DAMON.
Leer descripción completaMostrar menos
The reads for parameters committing are protected by damon_sysfs_lock to avoid the sysfs files being destroyed while any of the parameters are being read. But the user-driven direct reads and writes are not protected by any lock, while the write is deallocating the memcg_path-pointing buffer. As a result, the readers could read the already freed buffer (user-after-free). Note that the user-reads don't race when the same open file is used by the writer, due to kernfs's open file locking. Nonetheless, doing the reads and writes with separate open files would be common. Fix it by protecting both the user-direct reads and writes with damon_sysfs_lock.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1059Command and Scripting Interpreterexecution70 % - Impacto secundario
T1499.004Application or System Exploitationimpact60 %
Vulnerabilidad local (AV:L/PR:L) de use-after-free en kernel Linux que permite escalada de privilegios mediante lectura/escritura de memoria. Ejecución de código o denegación de servicio posibles al acceder a buffer liberado.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-416
Referencias
- https://git.kernel.org/stable/c/1e68eb96e8beb1abefd12dd22c5637795d8a877e
- https://git.kernel.org/stable/c/b1e9f2d5870776347edef927f9bb3ea19b8e3abb
- https://git.kernel.org/stable/c/baecc45ad60e621ef14d6c1e7f41ef36bbfdf910
- https://git.kernel.org/stable/c/c88802d0e8edd14b6cd2daf3000f99adbc4c85c5
- https://git.kernel.org/stable/c/eafd6f5372d29b0dd213799b92c2c9c7ad31d7da
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-46121",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "490a43d07f1663d827e802720d30cbc0494e4f81",
"lessThan": "b1e9f2d5870776347edef927f9bb3ea19b8e3abb",
"versionType": "git"
},
{
"status": "affected",
"version": "c5d5b0047b0c0f304608f3824139f7bd34c48413",
"lessThan": "c88802d0e8edd14b6cd2daf3000f99adbc4c85c5",
"versionType": "git"
},
{
"status": "affected",
"version": "4f489fe6afb395dbc79840efa3c05440b760d883",
"lessThan": "eafd6f5372d29b0dd213799b92c2c9c7ad31d7da",
"versionType": "git"
},
{
"status": "affected",
"version": "4f489fe6afb395dbc79840efa3c05440b760d883",
"lessThan": "baecc45ad60e621ef14d6c1e7f41ef36bbfdf910",
"versionType": "git"
},
{
"status": "affected",
"version": "4f489fe6afb395dbc79840efa3c05440b760d883",
"lessThan": "1e68eb96e8beb1abefd12dd22c5637795d8a877e",
"versionType": "git"
},
{
"status": "affected",
"version": "4a158ac0538dd5695eeaa00aa0720d711f3e4ef1",
"versionType": "git"
},
{
"status": "affected",
"version": "6.6.96",
"lessThan": "6.6.140",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.12.36",
"lessThan": "6.12.88",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.15.5",
"lessThan": "6.16",
"versionType": "semver"
}
],
"programFiles": [
"mm/damon/sysfs-schemes.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.16"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.16",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.140",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.88",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.30",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.0.7",
"versionType": "semver",
"lessThanOrEqual": "7.0.*"
},
{
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"mm/damon/sysfs-schemes.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-05-28T10:16:27.600",
"references": [
{
"url": "https://git.kernel.org/stable/c/1e68eb96e8beb1abefd12dd22c5637795d8a877e",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b1e9f2d5870776347edef927f9bb3ea19b8e3abb",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/baecc45ad60e621ef14d6c1e7f41ef36bbfdf910",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c88802d0e8edd14b6cd2daf3000f99adbc4c85c5",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/eafd6f5372d29b0dd213799b92c2c9c7ad31d7da",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Undergoing Analysis",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-416"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock\n\nPatch series \"mm/damon/sysfs-schemes: fix use-after-free for [memcg_]path\".\n\nReads of 'memcg_path' and 'path' files in DAMON sysfs interface could race\nwith their writes, results in use-after-free. Fix those.\n\n\nThis patch (of 2):\n\ndamon_sysfs_scheme_filter->mmecg_path can be read and written by users,\nvia DAMON sysfs memcg_path file. It can also be indirectly read, for the\nparameters {on,off}line committing to DAMON. The reads for parameters\ncommitting are protected by damon_sysfs_lock to avoid the sysfs files\nbeing destroyed while any of the parameters are being read. But the\nuser-driven direct reads and writes are not protected by any lock, while\nthe write is deallocating the memcg_path-pointing buffer. As a result,\nthe readers could read the already freed buffer (user-after-free). Note\nthat the user-reads don't race when the same open file is used by the\nwriter, due to kernfs's open file locking. Nonetheless, doing the reads\nand writes with separate open files would be common. Fix it by protecting\nboth the user-direct reads and writes with damon_sysfs_lock."
}
],
"lastModified": "2026-06-24T16:51:34.720",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6F59F59B-0B5E-4FDE-9C04-14918F1FC132",
"versionEndExcluding": "6.6.140",
"versionStartIncluding": "6.6.96"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5BDE39B7-94D9-46FE-800D-F242F5EF34BD",
"versionEndExcluding": "6.12.88",
"versionStartIncluding": "6.12.36"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D10C9120-0117-4346-95CC-E5D06B9133C4",
"versionEndExcluding": "6.16",
"versionStartIncluding": "6.15.5"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A544F5E4-2BCE-4FFA-98B2-08E08A05FF7E",
"versionEndExcluding": "6.18.30",
"versionStartIncluding": "6.16.1"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D0893CA7-9AE6-4DFE-AC75-48967D73AD8E",
"versionEndExcluding": "7.0.7",
"versionStartIncluding": "6.19"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.16:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6238B17D-C12B-458F-A138-97039BFC4595"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A0517869-312D-4429-80C2-561086E1421C"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "85421F4E-C863-4ABF-B4B4-E887CC2F7F92"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3827F0D4-5FEE-4181-B267-5A45E7CA11FC"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A9C2DE5-43B8-4D73-BDB5-EA55C7671A52"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B1EF7059-E670-45F4-B422-54C40FA86390"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}