All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-64458: mm/damon/ops-common: handle extreme intervals in damon_hot_score()
@ 2026-07-25  8:51 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-07-25  8:51 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

mm/damon/ops-common: handle extreme intervals in damon_hot_score()

Fix three issues in damon_hot_score() that comes from wrong handling of
extreme (zero or too high) monitoring intervals user setup.

When the user sets sampling interval zero, damon_max_nr_accesses(), which
is called from damon_hot_score(), causes a divide-by-zero.  Needless to
say, it is a problem.

When the user sets the aggregation interval zero, the function returns
zero.  It is wrong, since the real maximum nr_acceses in the setup should
be one.  Worse yet, it can cause another divide-by-zero from its caller,
damon_hot_score(), since it uses damon_max_nr_accesses() return value as a
denominator.

When the user sets the aggregation interval very high, damon_hot_score()
could return a value out of [0, DAMOS_MAX_SCORE] range.  Since the return
value is used as an index to the regions_score_histogram array, which is
DAMOS_MAX_SCORE+1 size, it causes out of bounds array access.

The issues can be relatively easily reproduced like below.  The sysfs
write permission is required, though.

    # ./damo start --damos_action lru_prio --damos_quota_space 100M \
            --damos_quota_interval 1s
    # cd /sys/kernel/mm/damon/admin/kdamonds/0
    # echo 0 > contexts/0/monitoring_attrs/intervals/sample_us
    # echo 0 > contexts/0/monitoring_attrs/intervals/aggr_us
    # echo commit > state
    # dmesg
    [...]
    [  131.329762] Oops: divide error: 0000 [#1] SMP NOPTI
    [...]
    [  131.336089] RIP: 0010:damon_hot_score+0x27/0xd0
    [...]

Fix the divide-by-zero intervals problems by explicitly handling the zero
intervals in damon_max_nr_accesses().  Fix the out-of-bound array access
by applying [0, DAMOS_MAX_SCORE] bounds before returning from
damon_hot_score().

The issue was discovered [1] by Sashiko.

The Linux kernel CVE team has assigned CVE-2026-64458 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.16 with commit 198f0f4c58b9f481e4e51c8c70a6ab9852bbab7f and fixed in 6.1.178 with commit 58321b4e6e4f0f412069ab27ccdd56292757343a
	Issue introduced in 5.16 with commit 198f0f4c58b9f481e4e51c8c70a6ab9852bbab7f and fixed in 6.6.145 with commit 74fef68d521150281e36cdaa20e9e1ee3e3aa146
	Issue introduced in 5.16 with commit 198f0f4c58b9f481e4e51c8c70a6ab9852bbab7f and fixed in 6.12.96 with commit ef2ae10a4582bc92b7e944181bbd2f87f3d30f3a
	Issue introduced in 5.16 with commit 198f0f4c58b9f481e4e51c8c70a6ab9852bbab7f and fixed in 6.18.39 with commit 9c8f31eaae6140ecadec0c07320498a944556de2
	Issue introduced in 5.16 with commit 198f0f4c58b9f481e4e51c8c70a6ab9852bbab7f and fixed in 7.1.4 with commit 76e415ea88d20f022ed5cfcf78c50e156a267e91
	Issue introduced in 5.16 with commit 198f0f4c58b9f481e4e51c8c70a6ab9852bbab7f and fixed in 7.2-rc3 with commit 35d4a3cf70a855b50e53189ac2f8463e20a02046

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64458
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	include/linux/damon.h
	mm/damon/ops-common.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/58321b4e6e4f0f412069ab27ccdd56292757343a
	https://git.kernel.org/stable/c/74fef68d521150281e36cdaa20e9e1ee3e3aa146
	https://git.kernel.org/stable/c/ef2ae10a4582bc92b7e944181bbd2f87f3d30f3a
	https://git.kernel.org/stable/c/9c8f31eaae6140ecadec0c07320498a944556de2
	https://git.kernel.org/stable/c/76e415ea88d20f022ed5cfcf78c50e156a267e91
	https://git.kernel.org/stable/c/35d4a3cf70a855b50e53189ac2f8463e20a02046

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-07-25  9:00 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-25  8:51 CVE-2026-64458: mm/damon/ops-common: handle extreme intervals in damon_hot_score() Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.