Database/Kernel, userspace & hypervisor
Linux kernel DAMON: merge-threshold overflow can spin kdamond in an infinite in-kernel loop
Impact
kdamond_merge_regions() doubles its merge threshold until it passes a theoretical maximum. When that maximum exceeds UINT_MAX/2 the doubling overflows and skips the loop-exit check, so if the region count cannot be reduced the kernel thread loops forever, burning a core and stalling DAMON. Reaching it requires an operator-chosen aggregation-to-sampling interval ratio that is unrealistically large plus a large set of non-contiguous, unmergeable regions, and configuring DAMON requires privilege - the upstream series itself calls this unurgent and unlikely in the real world. For a GPU fleet the practical read is: if you do not drive DAMON tuning from an unprivileged or automated source, this is a hygiene fix, not a maintenance window.
Who can reach it
Local privileged user able to set DAMON monitoring parameters (sysfs/DAMON interface) to extreme values. Not reachable by tenants and not reachable at all where DAMON is unused.
What to do
Take the stable patches that check the break condition before doubling and clamp the threshold (commits in the record). It ships as a kernel update, so it rides along on the next drain-and-reboot cycle rather than justifying its own.
References
Related entries
- Linux qla2xxx: D_Port diagnostics copies uninitialized kernel heap bytes to user spaceCVE-2026-89859 · Linux kernel qla2xxx (D_Port diagnostics response buffer)Unscored
- KVM on s390: uninitialized stack bytes in injected pfault interrupt state readable via migration ioctlsCVE-2026-89921 · Linux kernel KVM/s390 (inject_pfault_token interrupt injection)Unscored
- Linux kernel dma-heap: failed copy_to_user leaks an already-installed dma-buf fd for process lifetimeCVE-2026-89996 · Linux kernel dma-buf dma-heap (DMA_HEAP_IOCTL_ALLOC)Unscored
- Linux kernel arm-smmu-v3: device teardown frees the IOPF queue before the IRQ handler that uses itCVE-2026-93205 · Linux kernel iommu/arm-smmu-v3 (teardown ordering in arm_smmu_device_remove)Unscored
- Linux kernel PCI/proc: config space read checked against the reader's credentials, not the opener'sCVE-2026-93206 · Linux kernel PCI procfs interface (proc_bus_pci_read CAP_SYS_ADMIN check)Unscored
- Linux kernel SCSI core: blocking tag allocation during error recovery can deadlock the EH threadCVE-2026-93781 · Linux kernel SCSI core (scsi_eh_lock_door tag allocation)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.