Memory leak in Linux kernel - CVE-2026-31653
Published: April 25, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a memory leak in DAMON_SYSFS repeat_call_control handling when damon_call() fails after the monitored virtual address process terminates. A local user can cause the monitored process to terminate before damon_call() is invoked to cause a denial of service.
The issue occurs when a DAMON context is created for monitoring a virtual address process and that process exits immediately before the call is made.