SB20260824177 - Missing Release of Resource after Effective Lifetime in Linux kernel damon



SB20260824177 - Missing Release of Resource after Effective Lifetime in Linux kernel damon

Published: August 24, 2026

Security Bulletin ID SB20260824177
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-74644)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource management in damon_migrate_pages() in mm/damon/ops-common.c when handling migration requests with an invalid target NUMA node identifier. A local user can trigger a migration request with an invalid target node identifier to cause a denial of service.

The issue can leave folios isolated from the LRU with extra references, causing pages to remain off the LRU and potentially pinned after the mapping is gone.


Remediation

Install update from vendor's website.