Integer overflow in Linux kernel - CVE-2026-89796
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an integer overflow in kdamond_merge_regions() in the DAMON core when merging DAMON regions after online parameter updates. A local user can configure DAMON with an excessively large aggregation interval and numerous non-contiguous regions to cause a denial of service.
Exploitation requires the region count to remain above the user-defined upper limit after aggressive merging.