CVE-2026-31653: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: dealloc repeat_call_control if damon_call() fails damon_call() for repeat_call_control of DAMON_SYSFS could fail if somehow the kdamond is stopped before the damon_call(). It could happen, for example, when te damon context was made for monitroing of a virtual address processes, and the process is terminated immediately, before the damon_call() invocation. In the case, the dyanmically allocated repeat_call_control is not deallocated and leaked. Fix the leak by deallocating the repeat_call_control under the damon_call() failure. This issue is discovered by sashiko [1].
Affected products
- Linux Linux Kernel: from 6.17.1, before 6.18.23 (fixed in 6.18.23); from 6.19, before 6.19.13 (fixed in 6.19.13); version 6.17 only; version 7.0 only
Published 2026-04-24. Last modified 2026-06-17.