Memory leak in Linux kernel - CVE-2026-31652
Published: April 25, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a memory leak in damon_stat_start() when handling repeated writes to the "enabled" control after damon_call() failure. A local user can write Y to the "enabled" interface again after a failed damon_call() to cause a denial of service.
The issue occurs because the previously allocated damon_ctx object remains allocated after the failure condition.