Memory leak in Linux kernel - CVE-2026-23144
Published: February 16, 2026
Vulnerability identifier: #VU122858
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-23144
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the damon_sysfs_context_add_dirs() function in mm/damon/sysfs.c. A local user can perform a denial of service (DoS) attack.
Affected software
Linux kernel
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Ubuntu
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
kernel (Red Hat package)
kernel-rt (Red Hat package)
linux-fips (Ubuntu package)
linux (Ubuntu package)
linux-nvidia-tegra (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-nvidia-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
linux-azure-fde-6.17 (Ubuntu package)
linux-gcp-6.17 (Ubuntu package)
linux-oracle-6.17 (Ubuntu package)
linux-azure-6.17 (Ubuntu package)
linux-oem-6.17 (Ubuntu package)
linux-nvidia-6.17 (Ubuntu package)
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Ubuntu
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
kernel (Red Hat package)
kernel-rt (Red Hat package)
linux-fips (Ubuntu package)
linux (Ubuntu package)
linux-nvidia-tegra (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-nvidia-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
linux-azure-fde-6.17 (Ubuntu package)
linux-gcp-6.17 (Ubuntu package)
linux-oracle-6.17 (Ubuntu package)
linux-azure-6.17 (Ubuntu package)
linux-oem-6.17 (Ubuntu package)
linux-nvidia-6.17 (Ubuntu package)
How to mitigate CVE-2026-23144
Install update from vendor's repository.
kernel (Red Hat package) - addressed in versions 5.14.0-284.166.1.el9_2, 5.14.0-570.108.1.el9_6, 6.12.0-55.68.1.el10_0, 6.12.0-124.49.1.el10_1
kernel-rt (Red Hat package) - update to 5.14.0-284.166.1.rt14.451.el9_2
linux-fips (Ubuntu package) - update to 6.8.0-116.116+fips1
linux (Ubuntu package) - addressed in versions 6.8.0-117.117, 6.8.0-117.117.1, 6.8.0-117.117.1~22.04.1, 6.8.0-1041.44, 6.8.0-1054.60, 6.8.0-1055.56, 6.8.0-1055.56~22.04.1, 6.8.0-1055.58+fips1, 6.8.0-1056.60, 6.8.0-1058.61, 6.8.0-1058.61+fips1, 6.8.0-2045.46, 6.8.1-1051.52, 6.8.1-1051.52~22.04.1
linux-nvidia-tegra (Ubuntu package) - update to 6.8.0-1024.24
linux-nvidia (Ubuntu package) - addressed in versions 6.8.0-1054.57, 6.8.0-1054.57.1
linux-nvidia-6.8 (Ubuntu package) - update to 6.8.0-1054.57~22.04.1
linux-azure (Ubuntu package) - update to 6.8.0-1056.62
linux-azure-fde-6.17 (Ubuntu package) - update to 6.17.0-1018.18~24.04.1
linux-gcp-6.17 (Ubuntu package) - addressed in versions 6.17.0-1018.20~24.04.1, 6.17.0-1021.24~24.04.1
linux-oracle-6.17 (Ubuntu package) - addressed in versions 6.17.0-1019.19~24.04.3, 6.17.0-1019.19~24.04.3+1
linux-azure-6.17 (Ubuntu package) - update to 6.17.0-1021.21~24.04.1
linux-oem-6.17 (Ubuntu package) - update to 6.17.0-1030.30
linux-nvidia-6.17 (Ubuntu package) - update to 6.17.0-1031.31
kernel-rt (Red Hat package) - update to 5.14.0-284.166.1.rt14.451.el9_2
linux-fips (Ubuntu package) - update to 6.8.0-116.116+fips1
linux (Ubuntu package) - addressed in versions 6.8.0-117.117, 6.8.0-117.117.1, 6.8.0-117.117.1~22.04.1, 6.8.0-1041.44, 6.8.0-1054.60, 6.8.0-1055.56, 6.8.0-1055.56~22.04.1, 6.8.0-1055.58+fips1, 6.8.0-1056.60, 6.8.0-1058.61, 6.8.0-1058.61+fips1, 6.8.0-2045.46, 6.8.1-1051.52, 6.8.1-1051.52~22.04.1
linux-nvidia-tegra (Ubuntu package) - update to 6.8.0-1024.24
linux-nvidia (Ubuntu package) - addressed in versions 6.8.0-1054.57, 6.8.0-1054.57.1
linux-nvidia-6.8 (Ubuntu package) - update to 6.8.0-1054.57~22.04.1
linux-azure (Ubuntu package) - update to 6.8.0-1056.62
linux-azure-fde-6.17 (Ubuntu package) - update to 6.17.0-1018.18~24.04.1
linux-gcp-6.17 (Ubuntu package) - addressed in versions 6.17.0-1018.20~24.04.1, 6.17.0-1021.24~24.04.1
linux-oracle-6.17 (Ubuntu package) - addressed in versions 6.17.0-1019.19~24.04.3, 6.17.0-1019.19~24.04.3+1
linux-azure-6.17 (Ubuntu package) - update to 6.17.0-1021.21~24.04.1
linux-oem-6.17 (Ubuntu package) - update to 6.17.0-1030.30
linux-nvidia-6.17 (Ubuntu package) - update to 6.17.0-1031.31
External References
- https://git.kernel.org/stable/c/43964644348f6b1add3055c4a6cae8f77d892a6e
- https://git.kernel.org/stable/c/5651c0c391c0029541794f9c4c9597faecfd401f
- https://git.kernel.org/stable/c/78b4eb99751ebd37ceade78810bf94de80f7fb3a
- https://git.kernel.org/stable/c/9814cc832b88bd040fc2a1817c2b5469d0f7e862
- https://git.kernel.org/stable/c/db7dfe78fc81bdd2b532d77f340fe453f2360426
Related Security Bulletins
- Memory leak in Linux kernel damon
- Red Hat Enterprise Linux 10 update for kernel
- Red Hat Enterprise Linux 10 update for kernel
- Red Hat Enterprise Linux 9 update for kernel
- Red Hat Enterprise Linux 9 update for kernel-rt
- Red Hat Enterprise Linux 9 update for kernel
- Ubuntu update for linux
- Ubuntu update for linux-nvidia
- Ubuntu update for linux-fips
- Ubuntu update for linux-nvidia-tegra
- Ubuntu update for linux-nvidia-6.8
- Ubuntu update for linux-azure
- Ubuntu update for linux-gcp-6.17
- Ubuntu update for linux-oem-6.17
- Ubuntu update for linux-azure-fde-6.17
- Ubuntu update for linux-azure-6.17
- Ubuntu update for linux-oracle-6.17
- Ubuntu update for linux-nvidia-6.17