-

CVE-2026-72176

mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error

In the Linux kernel, the following vulnerability has been resolved:

mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error

damon_sysfs_scheme_add_dirs() setup the tried_regions directory after the
stats directory setup is completed.  When the tried_regions directory
setup is failed, the setup function ensures the reference for the tried
regions directory is released.  Hence the error path should put references
on setup succeeded directory objects, starting from the stats directory. 
However, the error path is putting the tried_regions directory instead of
the stats directory.

As a direct result, the stats directory object is leaked.  Worse yet, if
the tried_regions directory setup failed from the initial allocation, the
scheme->tried_regions field remains uninitialized.  The following
kobject_put(&scheme->tried_regions->kobj) call in the error path will
dereference the uninitialized memory.  The setup failures should not be
common.  But once it happens, the consequence is quite bad.

Fix this issue by correctly putting the stats directory instead of the
tried_regions directory.

The issue was discovered [1] by Sashiko.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 5181b75f438d2e5b7f27bf48c6ea88a87c2882b7
Version < 50a753171d255895e5dd41566986b48dcec06f31
Status affected
Version 5181b75f438d2e5b7f27bf48c6ea88a87c2882b7
Version < f63d6e5ba72aeacdee4fddc902bd7616cd62b919
Status affected
Version 5181b75f438d2e5b7f27bf48c6ea88a87c2882b7
Version < 40a04601a3f66cabd6629c258a07af645a658865
Status affected
Version 5181b75f438d2e5b7f27bf48c6ea88a87c2882b7
Version < 6b6b5d7c2c957136b92c00b77b7175259f13082b
Status affected
Version 5181b75f438d2e5b7f27bf48c6ea88a87c2882b7
Version < 05ea83ee88ca70f8932906d9f2617ff996f45b50
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.2
Status affected
Version 0
Version < 6.2
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/50a753171d255895e5dd41566986b48dcec06f31
https://git.kernel.org/stable/c/f63d6e5ba72aeacdee4fddc902bd7616cd62b919
https://git.kernel.org/stable/c/40a04601a3f66cabd6629c258a07af645a658865
https://git.kernel.org/stable/c/6b6b5d7c2c957136b92c00b77b7175259f13082b
https://git.kernel.org/stable/c/05ea83ee88ca70f8932906d9f2617ff996f45b50