CVE-2026-72176 (GCVE-0-2026-72176)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-17 05:09
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error
damon_sysfs_scheme_add_dirs() setup the tried_regions directory after the
stats directory setup is completed. When the tried_regions directory
setup is failed, the setup function ensures the reference for the tried
regions directory is released. Hence the error path should put references
on setup succeeded directory objects, starting from the stats directory.
However, the error path is putting the tried_regions directory instead of
the stats directory.
As a direct result, the stats directory object is leaked. Worse yet, if
the tried_regions directory setup failed from the initial allocation, the
scheme->tried_regions field remains uninitialized. The following
kobject_put(&scheme->tried_regions->kobj) call in the error path will
dereference the uninitialized memory. The setup failures should not be
common. But once it happens, the consequence is quite bad.
Fix this issue by correctly putting the stats directory instead of the
tried_regions directory.
The issue was discovered [1] by Sashiko.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/damon/sysfs-schemes.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "50a753171d255895e5dd41566986b48dcec06f31",
"status": "affected",
"version": "5181b75f438d2e5b7f27bf48c6ea88a87c2882b7",
"versionType": "git"
},
{
"lessThan": "f63d6e5ba72aeacdee4fddc902bd7616cd62b919",
"status": "affected",
"version": "5181b75f438d2e5b7f27bf48c6ea88a87c2882b7",
"versionType": "git"
},
{
"lessThan": "40a04601a3f66cabd6629c258a07af645a658865",
"status": "affected",
"version": "5181b75f438d2e5b7f27bf48c6ea88a87c2882b7",
"versionType": "git"
},
{
"lessThan": "6b6b5d7c2c957136b92c00b77b7175259f13082b",
"status": "affected",
"version": "5181b75f438d2e5b7f27bf48c6ea88a87c2882b7",
"versionType": "git"
},
{
"lessThan": "05ea83ee88ca70f8932906d9f2617ff996f45b50",
"status": "affected",
"version": "5181b75f438d2e5b7f27bf48c6ea88a87c2882b7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/damon/sysfs-schemes.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.2"
},
{
"lessThan": "6.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error\n\ndamon_sysfs_scheme_add_dirs() setup the tried_regions directory after the\nstats directory setup is completed. When the tried_regions directory\nsetup is failed, the setup function ensures the reference for the tried\nregions directory is released. Hence the error path should put references\non setup succeeded directory objects, starting from the stats directory. \nHowever, the error path is putting the tried_regions directory instead of\nthe stats directory.\n\nAs a direct result, the stats directory object is leaked. Worse yet, if\nthe tried_regions directory setup failed from the initial allocation, the\nscheme-\u003etried_regions field remains uninitialized. The following\nkobject_put(\u0026scheme-\u003etried_regions-\u003ekobj) call in the error path will\ndereference the uninitialized memory. The setup failures should not be\ncommon. But once it happens, the consequence is quite bad.\n\nFix this issue by correctly putting the stats directory instead of the\ntried_regions directory.\n\nThe issue was discovered [1] by Sashiko."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:09:38.651Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/50a753171d255895e5dd41566986b48dcec06f31"
},
{
"url": "https://git.kernel.org/stable/c/f63d6e5ba72aeacdee4fddc902bd7616cd62b919"
},
{
"url": "https://git.kernel.org/stable/c/40a04601a3f66cabd6629c258a07af645a658865"
},
{
"url": "https://git.kernel.org/stable/c/6b6b5d7c2c957136b92c00b77b7175259f13082b"
},
{
"url": "https://git.kernel.org/stable/c/05ea83ee88ca70f8932906d9f2617ff996f45b50"
}
],
"title": "mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72176",
"datePublished": "2026-08-15T05:53:40.759Z",
"dateReserved": "2026-08-09T03:40:39.910Z",
"dateUpdated": "2026-08-17T05:09:38.651Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…