Description
In the Linux kernel, the following vulnerability has been resolved:

mm/damon/core: handle region split failure in apply_min_nr_regions()

damon_apply_min_nr_regions() repeatedly split each region until its size
becomes small enough to meet the user-defined low limit of the number of
regions. The loop assumes the split operation (damon_split_region_at())
will always succeed and create the new region. But the operation could
silently fail for memory allocation failures, for example.

If such failure happens and the region was the last region, the linked
list-based next region fetching returns invalid pointer. As a result,
invalid memory dereference and corruption could happen. Even if the
corner case is handled, it imposes stress to the allocator by trying split
regions for other targets. Fix the issue by breaking all the loops for
any region split failure.

This means there could be a min_nr_regions violation. It will only rarely
happen since the allocation is arguably too small to fail. Even if it
happens, it is only temporal. damon_apply_min_nr_regions() will be called
again after the aggregation interval.

The user impact of the issue should be minor, since the allocation is
arguably too small to fail. But, it could still theoretically happen, and
the consequence is very bad.

This issue was discovered [1] by Sashiko.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel’s DAMON subsystem, the function damon_apply_min_nr_regions repeatedly splits memory regions until each region meets a user‑defined lower bound. The split routine can silently fail when memory allocation for a new region is not possible. If the failure occurs while processing the last region in the list, the linked list traversal returns an invalid pointer, leading to an invalid memory dereference and corruption. Although the allocation is small and failures are rare, any occurrence would result in kernel memory corruption, which could compromise system integrity.

Affected Systems

The vulnerability exists in all Linux kernels that include the damon_core implementation and have not yet incorporated the patch found in commit 463ebd63e8ee3d73022a18915ea43320dad8aad7. The affected vendor is Linux, and version information is not explicitly listed, so all current releases prior to the fix are considered vulnerable.

Risk and Exploitability

The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of current exploitation. However, the impact—a potential kernel memory corruption—has severe and could allow privilege escalation or denial of service if an attacker can trigger the region‑split failure. Attackers would need local kernel access to influence DAMON operations or force an allocation failure. The likely attack vector is local kernel access to manipulate DAMON operations, inferred from the description. The severity remains low to medium pending exploitation evidence, but the damage scope is system‑wide if triggered.

Generated by OpenCVE AI on September 18, 2026 at 03:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel version that includes the damon_apply_min_nr_regions fix (commit 463ebd63e8ee… or later).
  • Enable kernel OOM and memory allocation debugging tools to detect and report allocation failures, ensuring proper handling is enforced.
  • Monitor system stability and, if risk remains high, consider disabling DAMON functionality until a patch is applied.

Generated by OpenCVE AI on September 18, 2026 at 03:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: handle region split failure in apply_min_nr_regions() damon_apply_min_nr_regions() repeatedly split each region until its size becomes small enough to meet the user-defined low limit of the number of regions. The loop assumes the split operation (damon_split_region_at()) will always succeed and create the new region. But the operation could silently fail for memory allocation failures, for example. If such failure happens and the region was the last region, the linked list-based next region fetching returns invalid pointer. As a result, invalid memory dereference and corruption could happen. Even if the corner case is handled, it imposes stress to the allocator by trying split regions for other targets. Fix the issue by breaking all the loops for any region split failure. This means there could be a min_nr_regions violation. It will only rarely happen since the allocation is arguably too small to fail. Even if it happens, it is only temporal. damon_apply_min_nr_regions() will be called again after the aggregation interval. The user impact of the issue should be minor, since the allocation is arguably too small to fail. But, it could still theoretically happen, and the consequence is very bad. This issue was discovered [1] by Sashiko.
Title mm/damon/core: handle region split failure in apply_min_nr_regions()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:33:14.085Z

Reserved: 2026-09-11T19:38:34.780Z

Link: CVE-2026-90004

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:12.997

Modified: 2026-09-16T11:17:12.997

Link: CVE-2026-90004

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:15:02Z

Weaknesses