PT-2026-43887 · Linux · Linux Kernel
CVE-2026-46020
·
Published
2026-05-27
·
Updated
2026-07-24
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 7.0.11-1.1
Description
Privileged users can trigger an out-of-bounds memory access via DAMON SYSFS. The issue occurs because the node ID in
damos quota goal->nid for node mem used bp and node mem free bp is used in si meminfo node() and NODE DATA() without proper validation. This allows the setting of arbitrary values for the node ID, potentially leading to a kernel NULL pointer dereference.Recommendations
Update to version 7.0.11-1.1.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel