CVE-2026-72176 (GCVE-0-2026-72176)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-17 05:09
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error damon_sysfs_scheme_add_dirs() setup the tried_regions directory after the stats directory setup is completed. When the tried_regions directory setup is failed, the setup function ensures the reference for the tried regions directory is released. Hence the error path should put references on setup succeeded directory objects, starting from the stats directory. However, the error path is putting the tried_regions directory instead of the stats directory. As a direct result, the stats directory object is leaked. Worse yet, if the tried_regions directory setup failed from the initial allocation, the scheme->tried_regions field remains uninitialized. The following kobject_put(&scheme->tried_regions->kobj) call in the error path will dereference the uninitialized memory. The setup failures should not be common. But once it happens, the consequence is quite bad. Fix this issue by correctly putting the stats directory instead of the tried_regions directory. The issue was discovered [1] by Sashiko.
Impacted products
Vendor Product Version
Linux Linux Version: 5181b75f438d2e5b7f27bf48c6ea88a87c2882b7
Version: 5181b75f438d2e5b7f27bf48c6ea88a87c2882b7
Version: 5181b75f438d2e5b7f27bf48c6ea88a87c2882b7
Version: 5181b75f438d2e5b7f27bf48c6ea88a87c2882b7
Version: 5181b75f438d2e5b7f27bf48c6ea88a87c2882b7
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "mm/damon/sysfs-schemes.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "50a753171d255895e5dd41566986b48dcec06f31",
              "status": "affected",
              "version": "5181b75f438d2e5b7f27bf48c6ea88a87c2882b7",
              "versionType": "git"
            },
            {
              "lessThan": "f63d6e5ba72aeacdee4fddc902bd7616cd62b919",
              "status": "affected",
              "version": "5181b75f438d2e5b7f27bf48c6ea88a87c2882b7",
              "versionType": "git"
            },
            {
              "lessThan": "40a04601a3f66cabd6629c258a07af645a658865",
              "status": "affected",
              "version": "5181b75f438d2e5b7f27bf48c6ea88a87c2882b7",
              "versionType": "git"
            },
            {
              "lessThan": "6b6b5d7c2c957136b92c00b77b7175259f13082b",
              "status": "affected",
              "version": "5181b75f438d2e5b7f27bf48c6ea88a87c2882b7",
              "versionType": "git"
            },
            {
              "lessThan": "05ea83ee88ca70f8932906d9f2617ff996f45b50",
              "status": "affected",
              "version": "5181b75f438d2e5b7f27bf48c6ea88a87c2882b7",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "mm/damon/sysfs-schemes.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.2"
            },
            {
              "lessThan": "6.2",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.1.*",
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.145",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.97",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.40",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1.5",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error\n\ndamon_sysfs_scheme_add_dirs() setup the tried_regions directory after the\nstats directory setup is completed.  When the tried_regions directory\nsetup is failed, the setup function ensures the reference for the tried\nregions directory is released.  Hence the error path should put references\non setup succeeded directory objects, starting from the stats directory. \nHowever, the error path is putting the tried_regions directory instead of\nthe stats directory.\n\nAs a direct result, the stats directory object is leaked.  Worse yet, if\nthe tried_regions directory setup failed from the initial allocation, the\nscheme-\u003etried_regions field remains uninitialized.  The following\nkobject_put(\u0026scheme-\u003etried_regions-\u003ekobj) call in the error path will\ndereference the uninitialized memory.  The setup failures should not be\ncommon.  But once it happens, the consequence is quite bad.\n\nFix this issue by correctly putting the stats directory instead of the\ntried_regions directory.\n\nThe issue was discovered [1] by Sashiko."
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-17T05:09:38.651Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/50a753171d255895e5dd41566986b48dcec06f31"
        },
        {
          "url": "https://git.kernel.org/stable/c/f63d6e5ba72aeacdee4fddc902bd7616cd62b919"
        },
        {
          "url": "https://git.kernel.org/stable/c/40a04601a3f66cabd6629c258a07af645a658865"
        },
        {
          "url": "https://git.kernel.org/stable/c/6b6b5d7c2c957136b92c00b77b7175259f13082b"
        },
        {
          "url": "https://git.kernel.org/stable/c/05ea83ee88ca70f8932906d9f2617ff996f45b50"
        }
      ],
      "title": "mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-72176",
    "datePublished": "2026-08-15T05:53:40.759Z",
    "dateReserved": "2026-08-09T03:40:39.910Z",
    "dateUpdated": "2026-08-17T05:09:38.651Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…