SB20260824177 - Missing Release of Resource after Effective Lifetime in Linux kernel damon
Published: August 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-74644)
CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in damon_migrate_pages() in mm/damon/ops-common.c when handling migration requests with an invalid target NUMA node identifier. A local user can trigger a migration request with an invalid target node identifier to cause a denial of service.
The issue can leave folios isolated from the LRU with extra references, causing pages to remain off the LRU and potentially pinned after the mapping is gone.
Remediation
Install update from vendor's website.