Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-74644

 

Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-74644

Published: August 24, 2026


Vulnerability identifier: #VU144897
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74644
CWE-ID: CWE-772
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource management in damon_migrate_pages() in mm/damon/ops-common.c when handling migration requests with an invalid target NUMA node identifier. A local user can trigger a migration request with an invalid target node identifier to cause a denial of service.

The issue can leave folios isolated from the LRU with extra references, causing pages to remain off the LRU and potentially pinned after the mapping is gone.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-74644

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins