Back to overview

CVE-2026-52905

Description
In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: disallow non-power of two min_region_sz on damon_start() Commit d8f867fa0825 ("mm/damon: add damon_ctx->min_sz_region") introduced a bug that allows unaligned DAMON region address ranges. Commit c80f46ac228b ("mm/damon/core: disallow non-power of two min_region_sz") fixed it, but only for damon_commit_ctx() use case. Still, DAMON sysfs interface can emit non-power of two min_region_sz via damon_start(). Fix the path by adding the is_power_of_2() check on damon_start(). The issue was discovered by sashiko [1].

Metadata

CVE ID
CVE-2026-52905
State
PUBLISHED
Assigner
Linux
Reserved
2026-06-09 07:44 UTC
Published
2026-06-09 12:36 UTC
Last updated
2026-06-09 12:36 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux d8f867fa0825fb3e358457566d7326d8aab2406a < 1de2db19a6028abe7d905875922faef5b873de67, d8f867fa0825fb3e358457566d7326d8aab2406a < 89b6226b6c2a4add3939f361653a47c212d6ab75, d8f867fa0825fb3e358457566d7326d8aab2406a < 95093e5cb4c5b50a5b1a4b79f2942b62744bd66a
Linux Linux 6.18, 0 < 6.18, 6.18.30 ≤ 6.18.*, 7.0.4 ≤ 7.0.* …
Back to overview