CVE-2026-31458

Updated on 22 Apr 2026

Severity

5.5 Medium severity

Details

CVSS score
5.5

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: check contexts->nr before accessing contexts_arr[0] Multiple sysfs command paths dereference contexts_arr[0] without first verifying that kdamond->contexts->nr == 1. A user can set nr_contexts to 0 via sysfs while DAMON is running, causing NULL pointer dereferences. In more detail, the issue can be triggered by privileged users like below. First, start DAMON and make contexts directory empty (kdamond->contexts->nr == 0).

damo start

cd /sys/kernel/mm/damon/admin/kdamonds/0

echo 0 > contexts/nr_contexts

Then, each of below commands will cause the NULL pointer dereference.

echo update_schemes_stats > state

echo update_schemes_tried_regions > state

echo update_schemes_tried_bytes > state

echo update_schemes_effective_quotas > state

echo update_tuned_intervals > state

Guard all commands (except OFF) at the entry point of damon_sysfs_handle_cmd(). A flaw was found in the Linux kernel. A privileged local user can exploit this by manipulating the nr_contexts parameter in the mm/damon/sysfs interface to zero while the DAMON (Data Access MONitor) subsystem is active. This leads to a null pointer dereference when certain sysfs commands are subsequently executed, potentially causing a system crash and a Denial of Service (DoS).

Details

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Amazon Linux 2023 Planned
Debian 13 Planned
Ubuntu 24.04 Planned