GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel DAMON: merge-threshold overflow can spin kdamond in an infinite in-kernel loop

UnscoredCVE-2026-89796Kernel, userspace & hypervisorcurated

Impact

kdamond_merge_regions() doubles its merge threshold until it passes a theoretical maximum. When that maximum exceeds UINT_MAX/2 the doubling overflows and skips the loop-exit check, so if the region count cannot be reduced the kernel thread loops forever, burning a core and stalling DAMON. Reaching it requires an operator-chosen aggregation-to-sampling interval ratio that is unrealistically large plus a large set of non-contiguous, unmergeable regions, and configuring DAMON requires privilege - the upstream series itself calls this unurgent and unlikely in the real world. For a GPU fleet the practical read is: if you do not drive DAMON tuning from an unprivileged or automated source, this is a hygiene fix, not a maintenance window.

Who can reach it

Local privileged user able to set DAMON monitoring parameters (sysfs/DAMON interface) to extreme values. Not reachable by tenants and not reachable at all where DAMON is unused.

What to do

Take the stable patches that check the break condition before doubling and clamp the threshold (commits in the record). It ships as a kernel update, so it rides along on the next drain-and-reboot cycle rather than justifying its own.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.