Impact
The vulnerability resides in the DAMON component of the Linux kernel. A flaw in the kdamond_merge_regions() routine can cause an infinite loop when the number of monitored regions exceeds the user‑defined upper limit and the internal merge threshold is forced beyond the theoretical maximum. This loop drains CPU resources and can render the kernel unresponsive, effectively a denial‑of‑service condition. The additional null‑pointer dereference mentioned in the patch applies only to a unit test and does not affect a production build, while any degradation in monitoring results is trivial best‑effort damage.
Affected Systems
This bug is present in all releases of the Linux kernel that include the DAMON memory‑monitoring infrastructure, without a specific version range listed. All Linux kernel builds that rely on DAMON are potentially affected until the patch is applied.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalogue, indicating a very low probability of widespread exploitation. The attack is highly contingent on an attacker configuring DAMON with exotic parameters—unrealistically large aggregation intervals and a huge number of non‑contiguous regions—which is unlikely to happen in a typical deployment. Consequently, the risk to most installations is modest, but the impact of the infinite loop could be severe if the specific conditions are met.
OpenCVE Enrichment
Debian DLA
Debian DSA