CVE-2026-31652

Source
https://cve.org/CVERecord?id=CVE-2026-31652
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-31652.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-31652
Downstream
Published
2026-04-24T14:45:04Z
Modified
2026-08-12T03:51:25Z
Summary
mm/damon/stat: deallocate damon_call() failure leaking damon_ctx
Details

In the Linux kernel, the following vulnerability has been resolved:

mm/damon/stat: deallocate damon_call() failure leaking damon_ctx

damon_stat_start() always allocates the module's damon_ctx object (damon_stat_context). Meanwhile, if damon_call() in the function fails, the damon_ctx object is not deallocated. Hence, if the damon_call() is failed, and the user writes Y to “enabled” again, the previously allocated damon_ctx object is leaked.

This cannot simply be fixed by deallocating the damon_ctx object when damon_call() fails. That's because damon_call() failure doesn't guarantee the kdamond main function, which accesses the damon_ctx object, is completely finished. In other words, if damon_stat_start() deallocates the damon_ctx object after damon_call() failure, the not-yet-terminated kdamond could access the freed memory (use-after-free).

Fix the leak while avoiding the use-after-free by keeping returning damon_stat_start() without deallocating the damon_ctx object after damon_call() failure, but deallocating it when the function is invoked again and the kdamond is completely terminated. If the kdamond is not yet terminated, simply return -EAGAIN, as the kdamond will soon be terminated.

The issue was discovered [1] by sashiko.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31652.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
405f61996d9d2e9d497cd9f6b66f41dc28d3d1d8
Fixed
447f8870b484f6596d7a7130e72bd0a3f1e037bb
Fixed
16c92e9bf55fa049ddb5e894dc0623dacd46a620
Fixed
4c04c6b47c361612b1d70cec8f7a60b1482d1400

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-31652.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.17.0
Fixed
6.18.23
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.13

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-31652.json"