Impact
The Linux kernel’s DAMON sample modules fail to release allocated resources when damon_start() returns an error. This oversight causes memory leaks, disrupts subsequent DAMON operations, and may lead to use‑after‑free conditions if the stale context is later accessed. The flaw is triggered by the kernel’s caller logic, which incorrectly assumes that cleanup will be handled automatically and does not account for start‑failure cleanup paths.
Affected Systems
All Linux kernel distributions that include the DAMON sample modules (specifically wsse, mtier, and prcl). Reproduction requires privileged (sudo) access to start and configure these modules, but the impact is confined to systems where the affected sample modules are loaded.
Risk and Exploitability
The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the flaw is not listed in CISA’s KEV catalog. An attacker would need local administrative privileges to trigger damon_start() failures. While the vulnerability can cause resource exhaustion and kernel instability, the limited attack surface and the need for elevation reduce the overall risk compared to remote‑exploitable flaws.
OpenCVE Enrichment