Answer in brief
CVE-2026-46121 records a High severity (CVSS 7.8) vulnerability in mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=490a43d07f1663d827e802720d30cbc0494e4f81 <b1e9f2d5870776347edef927f9bb3ea19b8e3abb || >=c5d5b0047b0c0f304608f3824139f7bd34c48413 <c88802d0e8edd14b6cd2daf3000f99adbc4c85c5 || >=4f489fe6afb395dbc79840efa3c05440b760d883 <eafd6f5372d29b0dd213799b92c2c9c7ad31d7da || >=4f489fe6afb395dbc79840efa3c05440b760d883 <baecc45ad60e621ef14d6c1e7f41ef36bbfdf910 || >=4f489fe6afb395dbc79840efa3c05440b760d883 <1e68eb96e8beb1abefd12dd22c5637795d8a877e || 4a158ac0538dd5695eeaa00aa0720d711f3e4ef1 || >=6.6.96 <6.6.140 || >=6.12.36 <6.12.88 || >=6.15.5 <6.16 | b1e9f2d5870776347edef927f9bb3ea19b8e3abb, c88802d0e8edd14b6cd2daf3000f99adbc4c85c5, eafd6f5372d29b0dd213799b92c2c9c7ad31d7da, baecc45ad60e621ef14d6c1e7f41ef36bbfdf910, 1e68eb96e8beb1abefd12dd22c5637795d8a877e, 6.6.140, 6.12.88, 6.16 |
| Linux/Linuxgeneric | 6.16 | Not reported |
Published upstream
May 28, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jun 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 24, 2026
In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock Patch series "mm/damon/sysfs-schemes: fix use-after-free for [memcg_]path". Reads of 'memcg_path' and 'path' files in DAMON sysfs interface could race with their writes, results in use-after-free. Fix those. This patch (of 2): damon_sysfs_scheme_filter->mmecg_path can be read and written by users, via DAMON sysfs memcg_path file. It can also be indirectly read, for the parameters {on,off}line committing to DAMON. The reads for parameters committing are protected by damon_sysfs_lock to avoid the sysfs files being destroyed while any of the parameters are being read. But the user-driven direct reads and writes are not protected by any lock, while the write is deallocating the memcg_path-pointing buffer. As a result, the readers could read the already freed buffer (user-after-free). Note that the user-reads don't race when the same open file is used by the writer, due to kernfs's open file locking. Nonetheless, doing the reads and writes with separate open files would be common. Fix it by protecting both the user-direct reads and writes with damon_sysfs_lock.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-46121 records a High severity (CVSS 7.8) vulnerability in mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=490a43d07f1663d827e802720d30cbc0494e4f81 <b1e9f2d5870776347edef927f9bb3ea19b8e3abb || >=c5d5b0047b0c0f304608f3824139f7bd34c48413 <c88802d0e8edd14b6cd2daf3000f99adbc4c85c5 || >=4f489fe6afb395dbc79840efa3c05440b760d883 <eafd6f5372d29b0dd213799b92c2c9c7ad31d7da || >=4f489fe6afb395dbc79840efa3c05440b760d883 <baecc45ad60e621ef14d6c1e7f41ef36bbfdf910 || >=4f489fe6afb395dbc79840efa3c05440b760d883 <1e68eb96e8beb1abefd12dd22c5637795d8a877e || 4a158ac0538dd5695eeaa00aa0720d711f3e4ef1 || >=6.6.96 <6.6.140 || >=6.12.36 <6.12.88 || >=6.15.5 <6.16 | b1e9f2d5870776347edef927f9bb3ea19b8e3abb, c88802d0e8edd14b6cd2daf3000f99adbc4c85c5, eafd6f5372d29b0dd213799b92c2c9c7ad31d7da, baecc45ad60e621ef14d6c1e7f41ef36bbfdf910, 1e68eb96e8beb1abefd12dd22c5637795d8a877e, 6.6.140, 6.12.88, 6.16 |
| Linux/Linuxgeneric | 6.16 | Not reported |
Published upstream
May 28, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jun 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 24, 2026
In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock Patch series "mm/damon/sysfs-schemes: fix use-after-free for [memcg_]path". Reads of 'memcg_path' and 'path' files in DAMON sysfs interface could race with their writes, results in use-after-free. Fix those. This patch (of 2): damon_sysfs_scheme_filter->mmecg_path can be read and written by users, via DAMON sysfs memcg_path file. It can also be indirectly read, for the parameters {on,off}line committing to DAMON. The reads for parameters committing are protected by damon_sysfs_lock to avoid the sysfs files being destroyed while any of the parameters are being read. But the user-driven direct reads and writes are not protected by any lock, while the write is deallocating the memcg_path-pointing buffer. As a result, the readers could read the already freed buffer (user-after-free). Note that the user-reads don't race when the same open file is used by the writer, due to kernfs's open file locking. Nonetheless, doing the reads and writes with separate open files would be common. Fix it by protecting both the user-direct reads and writes with damon_sysfs_lock.
Quoted source text, attributed separately from HOL analysis.