CVE-2026-31459: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: fix param_ctx leak on damon_sysfs_new_test_ctx() failure Patch series "mm/damon/sysfs: fix memory leak and NULL dereference issues", v4. DAMON_SYSFS can leak memory under allocation failure, and do NULL pointer dereference when a privileged user make wrong sequences of control. Fix those. This patch (of 3): When damon_sysfs_new_test_ctx() fails in damon_sysfs_commit_input(), param_ctx is leaked because the early return skips the cleanup at the out label. Destroy param_ctx before returning.
Affected products
- Linux Linux Kernel: from 6.18.1, before 6.18.21 (fixed in 6.18.21); from 6.19, before 6.19.11 (fixed in 6.19.11); version 6.17.6 only; version 6.18 only; version 7.0 only
Published 2026-04-22. Last modified 2026-06-17.