SB20260828208 - Improper input validation in Linux kernel damon



SB20260828208 - Improper input validation in Linux kernel damon

Published: August 28, 2026

Security Bulletin ID SB20260828208
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Partial DoS

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper input validation (CVE-ID: CVE-2026-80592)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in samples/damon/mtier.c when handling sysfs writes that enable the mtier sample module with invalid address range parameters. A local user can write invalid address range values to trigger a kernel warning and cause a denial of service.

The issue can occur if node0 or node1 address parameters are not properly initialized, including cases where automatic node address detection is enabled and one of the nodes is memoryless.


Remediation

Install update from vendor's website.