CVE-2026-90004 is a vulnerability in Linux Kernel
Published on September 16, 2026
mm/damon/core: handle region split failure in apply_min_nr_regions()
In the Linux kernel, the following vulnerability has been resolved:
mm/damon/core: handle region split failure in apply_min_nr_regions()
damon_apply_min_nr_regions() repeatedly split each region until its size
becomes small enough to meet the user-defined low limit of the number of
regions. The loop assumes the split operation (damon_split_region_at())
will always succeed and create the new region. But the operation could
silently fail for memory allocation failures, for example.
If such failure happens and the region was the last region, the linked
list-based next region fetching returns invalid pointer. As a result,
invalid memory dereference and corruption could happen. Even if the
corner case is handled, it imposes stress to the allocator by trying split
regions for other targets. Fix the issue by breaking all the loops for
any region split failure.
This means there could be a min_nr_regions violation. It will only rarely
happen since the allocation is arguably too small to fail. Even if it
happens, it is only temporal. damon_apply_min_nr_regions() will be called
again after the aggregation interval.
The user impact of the issue should be minor, since the allocation is
arguably too small to fail. But, it could still theoretically happen, and
the consequence is very bad.
This issue was discovered [1] by Sashiko.
Products Associated with CVE-2026-90004
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version b1029f29eb1d5fbf07fa8db9b5e7ab6d9813ad67 and below 463ebd63e8ee3d73022a18915ea43320dad8aad7 is affected.
- Version b1029f29eb1d5fbf07fa8db9b5e7ab6d9813ad67 and below c608748607620f331196ed0ba9fe4017892c1457 is affected.
- Version 7.1 is affected.
- Before 7.1 is unaffected.
- Version 7.2.5, <= 7.2.* is unaffected.
- Version 7.3-rc1, <= * is unaffected.