CVE-2026-52905 is a vulnerability in Linux Kernel
Published on June 9, 2026
mm/damon/core: disallow non-power of two min_region_sz on damon_start()
In the Linux kernel, the following vulnerability has been resolved:
mm/damon/core: disallow non-power of two min_region_sz on damon_start()
Commit d8f867fa0825 ("mm/damon: add damon_ctx->min_sz_region") introduced
a bug that allows unaligned DAMON region address ranges. Commit
c80f46ac228b ("mm/damon/core: disallow non-power of two min_region_sz")
fixed it, but only for damon_commit_ctx() use case. Still, DAMON sysfs
interface can emit non-power of two min_region_sz via damon_start(). Fix
the path by adding the is_power_of_2() check on damon_start().
The issue was discovered by sashiko [1].
Products Associated with CVE-2026-52905
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version d8f867fa0825fb3e358457566d7326d8aab2406a and below 1de2db19a6028abe7d905875922faef5b873de67 is affected.
- Version d8f867fa0825fb3e358457566d7326d8aab2406a and below 89b6226b6c2a4add3939f361653a47c212d6ab75 is affected.
- Version d8f867fa0825fb3e358457566d7326d8aab2406a and below 95093e5cb4c5b50a5b1a4b79f2942b62744bd66a is affected.
- Version 6.18 is affected.
- Before 6.18 is unaffected.
- Version 6.18.30, <= 6.18.* is unaffected.
- Version 7.0.4, <= 7.0.* is unaffected.
- Version 7.1-rc1, <= * is unaffected.