Impact
A flaw in the Linux kernel’s DAMON mt a use‑after‑free when stopping DAMON contexts. The stop routine assumes all contexts halt successfully and deallocates memory for stopped contexts. If a context is already stopped, the routine fails for that one, leaving other contexts running; subsequent deallocation frees memory still in use by the running context, creating a use‑after‑free that an attacker could exploit to execute arbitrary code in kernel mode. The weakness is a classic use‑after‑free condition.
Affected Systems
This vulnerability is present in the core Linux kernel. No specific version numbers are listed, so any kernel revision that has not yet incorporated the fix is potentially affected.
Risk and Exploitability
The CVSS and exploitation probability are not quantified, but the EPSS score is reported as less than 1 % and the flaw is not listed in the CISA KEV catalog, indicating a low public exploit likelihood. However, because the issue involves kernel memory, exploitation would require a local attack that can influence the DAMON module, leading to privilege escalation or remote code execution if the attacker can control the stopping process. The precise attack vector would involve manipulating DAMON contexts or induced allocation failures in kdamond_fn().
OpenCVE Enrichment