Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-64184
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper release of a resource in damon_sysfs_memcg_path_to_id() in mm/damon/sysfs-schemes.c when iterating memory cgroups and breaking out of the mem_cgroup_iter() loop early. A local user can trigger the affected code path to cause a denial of service.
The issue results from a leaked cgroup reference because mem_cgroup_iter_break() is not called before exiting the iteration.
How to mitigate CVE-2026-64184
Sources
- https://git.kernel.org/stable/c/082351f9d40007414ad6af062b3a26fa02fd4b5f
- https://git.kernel.org/stable/c/1bd31386ec3b9ccec10c04429948a306ec5897c0
- https://git.kernel.org/stable/c/302e02f9ba49f81418ec2a749ae6f5cac1d424e9
- https://git.kernel.org/stable/c/30a361be33f3793b9ecbd10ab7be6d0564819b79
- https://git.kernel.org/stable/c/d4e7b5c4cc353f154d5ab8bb2e1ce7714d77a6e9