← Πίσω στην αναζήτηση CVE

CVE-2026-46183

Linux Kernel

Περιγραφή

In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: protect path kfree() with damon_sysfs_lock damon_sysfs_quot_goal->path can be read and written by users, via DAMON sysfs -path- file. It can also be indirectly read, for the parameters {on,off}line committing to DAMON. The reads for parameters committing are protected by damon_sysfs_lock to avoid the sysfs files being destroyed while any of the parameters are being read. But the user-driven direct reads and writes are not protected by any lock, while the write is deallocating the path-pointing buffer. As a result, the readers could read the already freed buffer (user-after-free). Note that the user-reads don-t race when the same open file is used by the writer, due to kernfs-s open file locking. Nonetheless, doing the reads and writes with separate open files would be common. Fix it by protecting both the user-direct reads and writes with damon_sysfs_lock.

CVSS 7.8EPSS 0.12%Κίνδυνος 0.79
Προβολή πηγής
Δημοσίευση
2026-05-28 10:16:33
Επηρεαζόμενες εκδόσεις
unknown
Τύπος
Core software
Διάνυσμα
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Λειτουργικά συστήματα
Linux