CVE-2026-52905 PUBLISHED

mm/damon/core: disallow non-power of two min_region_sz on damon_start()

Assigner: Linux
Reserved: 09.06.2026 Published: 09.06.2026 Updated: 09.06.2026

In the Linux kernel, the following vulnerability has been resolved:

mm/damon/core: disallow non-power of two min_region_sz on damon_start()

Commit d8f867fa0825 ("mm/damon: add damon_ctx->min_sz_region") introduced a bug that allows unaligned DAMON region address ranges. Commit c80f46ac228b ("mm/damon/core: disallow non-power of two min_region_sz") fixed it, but only for damon_commit_ctx() use case. Still, DAMON sysfs interface can emit non-power of two min_region_sz via damon_start(). Fix the path by adding the is_power_of_2() check on damon_start().

The issue was discovered by sashiko [1].

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from d8f867fa0825fb3e358457566d7326d8aab2406a to 1de2db19a6028abe7d905875922faef5b873de67 (excl.)
  • affected from d8f867fa0825fb3e358457566d7326d8aab2406a to 89b6226b6c2a4add3939f361653a47c212d6ab75 (excl.)
  • affected from d8f867fa0825fb3e358457566d7326d8aab2406a to 95093e5cb4c5b50a5b1a4b79f2942b62744bd66a (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.18 is affected
  • unaffected from 0 to 6.18 (excl.)
  • unaffected from 6.18.30 to 6.18.* (incl.)
  • unaffected from 7.0.4 to 7.0.* (incl.)
  • unaffected from 7.1-rc1 to * (incl.)

References