« Volver al listado

CVE-2026-90004

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

mm/damon/core: handle region split failure in apply_min_nr_regions()

damon_apply_min_nr_regions() repeatedly split each region until its size becomes small enough to meet the user-defined low limit of the number of regions. The loop assumes the split operation (damon_split_region_at()) will always succeed and create the new region. But the operation could silently fail for memory allocation failures, for example.

If such failure happens and the region was the last region, the linked list-based next region fetching returns invalid pointer. As a result, invalid memory dereference and corruption could happen.

Leer descripción completaMostrar menos

Even if the corner case is handled, it imposes stress to the allocator by trying split regions for other targets. Fix the issue by breaking all the loops for any region split failure.

This means there could be a min_nr_regions violation. It will only rarely happen since the allocation is arguably too small to fail. Even if it happens, it is only temporal. damon_apply_min_nr_regions() will be called again after the aggregation interval.

The user impact of the issue should be minor, since the allocation is arguably too small to fail. But, it could still theoretically happen, and the consequence is very bad.

This issue was discovered [1] by Sashiko.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90004",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "b1029f29eb1d5fbf07fa8db9b5e7ab6d9813ad67",
              "lessThan": "463ebd63e8ee3d73022a18915ea43320dad8aad7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b1029f29eb1d5fbf07fa8db9b5e7ab6d9813ad67",
              "lessThan": "c608748607620f331196ed0ba9fe4017892c1457",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "mm/damon/core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "mm/damon/core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:17:12.997",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/463ebd63e8ee3d73022a18915ea43320dad8aad7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c608748607620f331196ed0ba9fe4017892c1457",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/core: handle region split failure in apply_min_nr_regions()\n\ndamon_apply_min_nr_regions() repeatedly split each region until its size\nbecomes small enough to meet the user-defined low limit of the number of\nregions.  The loop assumes the split operation (damon_split_region_at())\nwill always succeed and create the new region.  But the operation could\nsilently fail for memory allocation failures, for example.\n\nIf such failure happens and the region was the last region, the linked\nlist-based next region fetching returns invalid pointer.  As a result,\ninvalid memory dereference and corruption could happen.  Even if the\ncorner case is handled, it imposes stress to the allocator by trying split\nregions for other targets.  Fix the issue by breaking all the loops for\nany region split failure.\n\nThis means there could be a min_nr_regions violation.  It will only rarely\nhappen since the allocation is arguably too small to fail.  Even if it\nhappens, it is only temporal.  damon_apply_min_nr_regions() will be called\nagain after the aggregation interval.\n\nThe user impact of the issue should be minor, since the allocation is\narguably too small to fail.  But, it could still theoretically happen, and\nthe consequence is very bad.\n\nThis issue was discovered [1] by Sashiko."
    }
  ],
  "lastModified": "2026-09-16T11:17:12.997",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}