-

CVE-2026-72178

mm/damon/core: always put unsuccessfully committed target pids

In the Linux kernel, the following vulnerability has been resolved:

mm/damon/core: always put unsuccessfully committed target pids

damon_commit_target() puts and gets the destination and the source target
pids.  It puts the destination target pid because it will be overwritten
by the source target pid.  It gets the source pid because the caller is
supposed to eventually put the pids.  In more detail, the caller will call
damon_destroy_ctx() after damon_commit_ctx() to destroy the entire source
context.  And in this case, [f]vaddr operation set's cleanup_target()
callback will put the pids.

The commit operation is made at the context level.  The operation can fail
in multiple places including in the middle and after the targets commit
operations.  For any such failures, immediately the error is returned to
the damon_commit_ctx() caller.  If some or all of the source target pids
were committed to the destination during the unsuccessful context commit
attempt, those pids should be put twice.

The source context will do the put operations using the above explained
routine.  However, let's suppose the destination context was not
originally using [f]vaddr operation set and the commit failed before the
ops of the source context is committed.  The destination does not have the
cleanup_target() ops callback, so it cannot put the pids via the
damon_destroy_ctx().

As a result, the pids are leaked.  The issue in the real world would be
not very common.  The commit feature is for changing parameters of running
DAMON context while inheriting internal status like the monitoring
results.  The monitoring results of a physical address range ain't have
things that are beneficial to be inherited to a virtual address ranges
monitoring.  So the problem-causing DAMON control would be not very common
in the real world.  That said, it is a supported feature.  And
damon_commit_target() failure due to memory allocation is relatively
realistic [1] if there are a huge number of target regions.

Fix by putting the pids in the commit operation in case of the failures.

The issue was discovered [2] by Sashiko.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 83dc7bbaecae6e69e338355e9a137f0e7a0ecc40
Version < ea07e045611ca00f1ec7e448fd43e655d311158b
Status affected
Version 83dc7bbaecae6e69e338355e9a137f0e7a0ecc40
Version < 3b91c35961fa5553b4dd36db1f06e3b4acbfc05d
Status affected
Version 83dc7bbaecae6e69e338355e9a137f0e7a0ecc40
Version < 837f619f1d98e967bd63e51ecd1e77bfa468992d
Status affected
Version 83dc7bbaecae6e69e338355e9a137f0e7a0ecc40
Version < 6a66c557a2ab2609575bafd15e093669c05f9711
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.11
Status affected
Version 0
Version < 6.11
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ea07e045611ca00f1ec7e448fd43e655d311158b
https://git.kernel.org/stable/c/3b91c35961fa5553b4dd36db1f06e3b4acbfc05d
https://git.kernel.org/stable/c/837f619f1d98e967bd63e51ecd1e77bfa468992d
https://git.kernel.org/stable/c/6a66c557a2ab2609575bafd15e093669c05f9711