CVE-2026-52905

In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: disallow non-power of two min_region_sz on damon_start() Commit d8f867fa0825 ("mm/damon: add damon_ctx->min_sz_region") introduced a bug that allows unaligned DAMON region address ranges. Commit c80f46ac228b ("mm/damon/core: disallow non-power of two min_region_sz") fixed it, but only for damon_commit_ctx() use case. Still, DAMON sysfs interface can emit non-power of two min_region_sz via damon_start(). Fix the path by adding the is_power_of_2() check on damon_start(). The issue was discovered by sashiko [1].
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: mm/damon/core: no permitir min_region_sz que no sea potencia de dos en damon_start() El commit d8f867fa0825 ('mm/damon: añadir damon_ctx->min_sz_region') introdujo un error que permite rangos de direcciones de región DAMON no alineados. El commit c80f46ac228b ('mm/damon/core: no permitir min_region_sz que no sea potencia de dos') lo solucionó, pero solo para el caso de uso de damon_commit_ctx(). Aun así, la interfaz sysfs de DAMON puede emitir min_region_sz que no sea potencia de dos a través de damon_start(). Solucionar la ruta añadiendo la comprobación is_power_of_2() en damon_start(). El problema fue descubierto por sashiko [1].

08 Jul 2026, 21:43

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/1de2db19a6028abe7d905875922faef5b873de67 - () https://git.kernel.org/stable/c/1de2db19a6028abe7d905875922faef5b873de67 - Patch
References () https://git.kernel.org/stable/c/89b6226b6c2a4add3939f361653a47c212d6ab75 - () https://git.kernel.org/stable/c/89b6226b6c2a4add3939f361653a47c212d6ab75 - Patch
References () https://git.kernel.org/stable/c/95093e5cb4c5b50a5b1a4b79f2942b62744bd66a - () https://git.kernel.org/stable/c/95093e5cb4c5b50a5b1a4b79f2942b62744bd66a - Patch
CWE CWE-1284
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

09 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 14:16

Updated : 2026-07-23 08:10


NVD link : CVE-2026-52905

Mitre link : CVE-2026-52905

CVE.ORG link : CVE-2026-52905


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-1284

Improper Validation of Specified Quantity in Input