CVE-2026-80592 (GCVE-0-2026-80592)
Vulnerability from cvelistv5
Published
2026-08-28 06:48
Modified
2026-08-28 06:48
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
samples/damon/mtier: fail early if address range parameters are invalid
The comment on top of `struct damon_region` clearly says that
For any use case, @ar should be non-zero positive size.
which is now verified in damon_verify_new_region() if the kernel is built
with DAMON_DEBUG_SANITY.
The WARN_ONCE() can be triggered if the mtier sample module is enabled
before node{0,1}_{start,end}_addr have been properly initialized, which is
obviously not good.
------------[ cut here ]------------
start 0 >= end 0
WARNING: mm/damon/core.c:217 at damon_new_region+0xf4/0x118, CPU#59: bash/341468
Call trace:
damon_new_region+0xf4/0x118 (P)
damon_set_regions+0xfc/0x3c0
damon_sample_mtier_build_ctx+0xe8/0x3a8
damon_sample_mtier_start+0x1c/0x90
damon_sample_mtier_enable_store+0x98/0xb0
param_attr_store+0xb4/0x128
module_attr_store+0x2c/0x50
sysfs_kf_write+0x58/0x90
kernfs_fop_write_iter+0x16c/0x238
vfs_write+0x2c0/0x370
ksys_write+0x74/0x118
__arm64_sys_write+0x24/0x38
invoke_syscall+0xa8/0x118
el0_svc_common.constprop.0+0x48/0xf0
do_el0_svc+0x24/0x38
el0_svc+0x54/0x370
el0t_64_sync_handler+0xa0/0xe8
el0t_64_sync+0x1ac/0x1b0
---[ end trace 0000000000000000 ]---
Note that the same issue can happen if detect_node_addresses is true, and
node 0 or 1 is memoryless. Fix it together by checking the validity of
parameters right before damon_new_region() and fail early if they're
invalid.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"samples/damon/mtier.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9d360fb820a3b9576d155e720ec44fef54d2efb5",
"status": "affected",
"version": "82a08bde3cf7bbbe90de57baa181bebf676582c7",
"versionType": "git"
},
{
"lessThan": "db20589d7b248211f63f4a7f642a49c0832b13ae",
"status": "affected",
"version": "82a08bde3cf7bbbe90de57baa181bebf676582c7",
"versionType": "git"
},
{
"lessThan": "7746d72c64054976887928d64d2caf25c5a6dcc0",
"status": "affected",
"version": "82a08bde3cf7bbbe90de57baa181bebf676582c7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"samples/damon/mtier.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.16"
},
{
"lessThan": "6.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsamples/damon/mtier: fail early if address range parameters are invalid\n\nThe comment on top of `struct damon_region` clearly says that\n\n For any use case, @ar should be non-zero positive size.\n\nwhich is now verified in damon_verify_new_region() if the kernel is built\nwith DAMON_DEBUG_SANITY.\n\nThe WARN_ONCE() can be triggered if the mtier sample module is enabled\nbefore node{0,1}_{start,end}_addr have been properly initialized, which is\nobviously not good.\n\n ------------[ cut here ]------------\n start 0 \u003e= end 0\n WARNING: mm/damon/core.c:217 at damon_new_region+0xf4/0x118, CPU#59: bash/341468\n Call trace:\n damon_new_region+0xf4/0x118 (P)\n damon_set_regions+0xfc/0x3c0\n damon_sample_mtier_build_ctx+0xe8/0x3a8\n damon_sample_mtier_start+0x1c/0x90\n damon_sample_mtier_enable_store+0x98/0xb0\n param_attr_store+0xb4/0x128\n module_attr_store+0x2c/0x50\n sysfs_kf_write+0x58/0x90\n kernfs_fop_write_iter+0x16c/0x238\n vfs_write+0x2c0/0x370\n ksys_write+0x74/0x118\n __arm64_sys_write+0x24/0x38\n invoke_syscall+0xa8/0x118\n el0_svc_common.constprop.0+0x48/0xf0\n do_el0_svc+0x24/0x38\n el0_svc+0x54/0x370\n el0t_64_sync_handler+0xa0/0xe8\n el0t_64_sync+0x1ac/0x1b0\n ---[ end trace 0000000000000000 ]---\n\nNote that the same issue can happen if detect_node_addresses is true, and\nnode 0 or 1 is memoryless. Fix it together by checking the validity of\nparameters right before damon_new_region() and fail early if they\u0027re\ninvalid."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-28T06:48:20.218Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9d360fb820a3b9576d155e720ec44fef54d2efb5"
},
{
"url": "https://git.kernel.org/stable/c/db20589d7b248211f63f4a7f642a49c0832b13ae"
},
{
"url": "https://git.kernel.org/stable/c/7746d72c64054976887928d64d2caf25c5a6dcc0"
}
],
"title": "samples/damon/mtier: fail early if address range parameters are invalid",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80592",
"datePublished": "2026-08-28T06:48:20.218Z",
"dateReserved": "2026-08-26T14:34:25.770Z",
"dateUpdated": "2026-08-28T06:48:20.218Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…