Description
In the Linux kernel, the following vulnerability has been resolved:

samples/damon/wsse: handle damon_start() failure

Patch series "samples/damon: handle damon_{start,stop}() failures".

All DAMON sample modules are not correctly handling failures from
damon_start(). Among those, mtier also has an additional problem for
handling of damon_stop() failures. wsse and prcl also have a problem in
their damon_call() failure handling. As a result, memory leaks, next
DAMON operation disruptions, and use-after-free can happen. Fix those.

Note that only the damon_start() failure caused issues can reliably be
reproduced. Reproducing those issues require the admin permission,
though.


This patch (of 6):

damon_sample_wsse_start() callers assume it will clean up resources when
it fails. And the function does the cleanup for context buildup failures.
However, it is not doing the cleanup for damon_start() failure. As a
result, when damon_start() fails, it leaks the memory for DAMON context.
Free the context in case of the failure to fix the issues.

Note that the issue can reliably be reproduced because the module calls
damon_start() in the exclusive mode. For example,

$ sudo damo start
$ echo $$ | sudo tee /sys/module/damon_sample_wsse/parameters/target_pid
$ echo Y | sudo tee /sys/module/damon_sample_wsse/parameters/enabled
$ sudo cat /proc/allocinfo | grep damon_new_ctx

Because the first command is running another DAMON instance, the third
command fails the damon_start() call because the new DAMON instance cannot
exclusively run. And without this fix, by repeating the third and the
fourth commands above, we can show the memory consumption is only
increasing due to the leaks. It requires the sudo permission though.

The issue was discovered [1] by Sashiko.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Memory Leak and Use-after-Free in DAMON Sample Modules
Action: Apply patch
AI Analysis

Impact

The Linux kernel’s DAMON sample modules fail to release allocated resources when damon_start() returns an error. This oversight causes memory leaks, disrupts subsequent DAMON operations, and may lead to use‑after‑free conditions if the stale context is later accessed. The flaw is triggered by the kernel’s caller logic, which incorrectly assumes that cleanup will be handled automatically and does not account for start‑failure cleanup paths.

Affected Systems

All Linux kernel distributions that include the DAMON sample modules (specifically wsse, mtier, and prcl). Reproduction requires privileged (sudo) access to start and configure these modules, but the impact is confined to systems where the affected sample modules are loaded.

Risk and Exploitability

The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the flaw is not listed in CISA’s KEV catalog. An attacker would need local administrative privileges to trigger damon_start() failures. While the vulnerability can cause resource exhaustion and kernel instability, the limited attack surface and the need for elevation reduce the overall risk compared to remote‑exploitable flaws.

Generated by OpenCVE AI on September 18, 2026 at 00:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official kernel patch that frees DAMON context on damon_start() failure
  • Stop any running DAMON instance before starting a new one to prevent exclusive mode conflicts
  • If the patch cannot be applied immediately, disable the DAMON sample modules or restrict access to trusted administrators
  • Monitor kernel memory usage via /proc/allocinfo or similar tools to detect ongoing leaks

Generated by OpenCVE AI on September 18, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401
CWE-416

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: samples/damon/wsse: handle damon_start() failure Patch series "samples/damon: handle damon_{start,stop}() failures". All DAMON sample modules are not correctly handling failures from damon_start(). Among those, mtier also has an additional problem for handling of damon_stop() failures. wsse and prcl also have a problem in their damon_call() failure handling. As a result, memory leaks, next DAMON operation disruptions, and use-after-free can happen. Fix those. Note that only the damon_start() failure caused issues can reliably be reproduced. Reproducing those issues require the admin permission, though. This patch (of 6): damon_sample_wsse_start() callers assume it will clean up resources when it fails. And the function does the cleanup for context buildup failures. However, it is not doing the cleanup for damon_start() failure. As a result, when damon_start() fails, it leaks the memory for DAMON context. Free the context in case of the failure to fix the issues. Note that the issue can reliably be reproduced because the module calls damon_start() in the exclusive mode. For example, $ sudo damo start $ echo $$ | sudo tee /sys/module/damon_sample_wsse/parameters/target_pid $ echo Y | sudo tee /sys/module/damon_sample_wsse/parameters/enabled $ sudo cat /proc/allocinfo | grep damon_new_ctx Because the first command is running another DAMON instance, the third command fails the damon_start() call because the new DAMON instance cannot exclusively run. And without this fix, by repeating the third and the fourth commands above, we can show the memory consumption is only increasing due to the leaks. It requires the sudo permission though. The issue was discovered [1] by Sashiko.
Title samples/damon/wsse: handle damon_start() failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:33:14.753Z

Reserved: 2026-09-11T19:38:34.780Z

Link: CVE-2026-90005

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:13.100

Modified: 2026-09-16T11:17:13.100

Link: CVE-2026-90005

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:30:16Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime

  • CWE-416

    Use After Free