{"api_version":"1","generated_at":"2026-09-02T16:37:38+00:00","cve":"CVE-2026-72178","urls":{"html":"https://cve.report/CVE-2026-72178","api":"https://cve.report/api/cve/CVE-2026-72178.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-72178","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-72178"},"summary":{"title":"mm/damon/core: always put unsuccessfully committed target pids","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/core: always put unsuccessfully committed target pids\n\ndamon_commit_target() puts and gets the destination and the source target\npids.  It puts the destination target pid because it will be overwritten\nby the source target pid.  It gets the source pid because the caller is\nsupposed to eventually put the pids.  In more detail, the caller will call\ndamon_destroy_ctx() after damon_commit_ctx() to destroy the entire source\ncontext.  And in this case, [f]vaddr operation set's cleanup_target()\ncallback will put the pids.\n\nThe commit operation is made at the context level.  The operation can fail\nin multiple places including in the middle and after the targets commit\noperations.  For any such failures, immediately the error is returned to\nthe damon_commit_ctx() caller.  If some or all of the source target pids\nwere committed to the destination during the unsuccessful context commit\nattempt, those pids should be put twice.\n\nThe source context will do the put operations using the above explained\nroutine.  However, let's suppose the destination context was not\noriginally using [f]vaddr operation set and the commit failed before the\nops of the source context is committed.  The destination does not have the\ncleanup_target() ops callback, so it cannot put the pids via the\ndamon_destroy_ctx().\n\nAs a result, the pids are leaked.  The issue in the real world would be\nnot very common.  The commit feature is for changing parameters of running\nDAMON context while inheriting internal status like the monitoring\nresults.  The monitoring results of a physical address range ain't have\nthings that are beneficial to be inherited to a virtual address ranges\nmonitoring.  So the problem-causing DAMON control would be not very common\nin the real world.  That said, it is a supported feature.  And\ndamon_commit_target() failure due to memory allocation is relatively\nrealistic [1] if there are a huge number of target regions.\n\nFix by putting the pids in the commit operation in case of the failures.\n\nThe issue was discovered [2] by Sashiko.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-15 06:21:36","updated_at":"2026-08-17 06:18:18"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/ea07e045611ca00f1ec7e448fd43e655d311158b","name":"https://git.kernel.org/stable/c/ea07e045611ca00f1ec7e448fd43e655d311158b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/6a66c557a2ab2609575bafd15e093669c05f9711","name":"https://git.kernel.org/stable/c/6a66c557a2ab2609575bafd15e093669c05f9711","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/837f619f1d98e967bd63e51ecd1e77bfa468992d","name":"https://git.kernel.org/stable/c/837f619f1d98e967bd63e51ecd1e77bfa468992d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/3b91c35961fa5553b4dd36db1f06e3b4acbfc05d","name":"https://git.kernel.org/stable/c/3b91c35961fa5553b4dd36db1f06e3b4acbfc05d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-72178","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72178","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 83dc7bbaecae6e69e338355e9a137f0e7a0ecc40 ea07e045611ca00f1ec7e448fd43e655d311158b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 83dc7bbaecae6e69e338355e9a137f0e7a0ecc40 3b91c35961fa5553b4dd36db1f06e3b4acbfc05d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 83dc7bbaecae6e69e338355e9a137f0e7a0ecc40 837f619f1d98e967bd63e51ecd1e77bfa468992d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 83dc7bbaecae6e69e338355e9a137f0e7a0ecc40 6a66c557a2ab2609575bafd15e093669c05f9711 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.11","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.11 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.97 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.40 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.5 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"72178","cve":"CVE-2026-72178","epss":"0.002000000","percentile":"0.101650000","score_date":"2026-08-17","updated_at":"2026-08-18 00:11:47"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["mm/damon/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"ea07e045611ca00f1ec7e448fd43e655d311158b","status":"affected","version":"83dc7bbaecae6e69e338355e9a137f0e7a0ecc40","versionType":"git"},{"lessThan":"3b91c35961fa5553b4dd36db1f06e3b4acbfc05d","status":"affected","version":"83dc7bbaecae6e69e338355e9a137f0e7a0ecc40","versionType":"git"},{"lessThan":"837f619f1d98e967bd63e51ecd1e77bfa468992d","status":"affected","version":"83dc7bbaecae6e69e338355e9a137f0e7a0ecc40","versionType":"git"},{"lessThan":"6a66c557a2ab2609575bafd15e093669c05f9711","status":"affected","version":"83dc7bbaecae6e69e338355e9a137f0e7a0ecc40","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["mm/damon/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.11"},{"lessThan":"6.11","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.97","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.40","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.97","versionStartIncluding":"6.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.40","versionStartIncluding":"6.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.5","versionStartIncluding":"6.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"6.11","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/core: always put unsuccessfully committed target pids\n\ndamon_commit_target() puts and gets the destination and the source target\npids.  It puts the destination target pid because it will be overwritten\nby the source target pid.  It gets the source pid because the caller is\nsupposed to eventually put the pids.  In more detail, the caller will call\ndamon_destroy_ctx() after damon_commit_ctx() to destroy the entire source\ncontext.  And in this case, [f]vaddr operation set's cleanup_target()\ncallback will put the pids.\n\nThe commit operation is made at the context level.  The operation can fail\nin multiple places including in the middle and after the targets commit\noperations.  For any such failures, immediately the error is returned to\nthe damon_commit_ctx() caller.  If some or all of the source target pids\nwere committed to the destination during the unsuccessful context commit\nattempt, those pids should be put twice.\n\nThe source context will do the put operations using the above explained\nroutine.  However, let's suppose the destination context was not\noriginally using [f]vaddr operation set and the commit failed before the\nops of the source context is committed.  The destination does not have the\ncleanup_target() ops callback, so it cannot put the pids via the\ndamon_destroy_ctx().\n\nAs a result, the pids are leaked.  The issue in the real world would be\nnot very common.  The commit feature is for changing parameters of running\nDAMON context while inheriting internal status like the monitoring\nresults.  The monitoring results of a physical address range ain't have\nthings that are beneficial to be inherited to a virtual address ranges\nmonitoring.  So the problem-causing DAMON control would be not very common\nin the real world.  That said, it is a supported feature.  And\ndamon_commit_target() failure due to memory allocation is relatively\nrealistic [1] if there are a huge number of target regions.\n\nFix by putting the pids in the commit operation in case of the failures.\n\nThe issue was discovered [2] by Sashiko."}],"providerMetadata":{"dateUpdated":"2026-08-17T05:09:40.842Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/ea07e045611ca00f1ec7e448fd43e655d311158b"},{"url":"https://git.kernel.org/stable/c/3b91c35961fa5553b4dd36db1f06e3b4acbfc05d"},{"url":"https://git.kernel.org/stable/c/837f619f1d98e967bd63e51ecd1e77bfa468992d"},{"url":"https://git.kernel.org/stable/c/6a66c557a2ab2609575bafd15e093669c05f9711"}],"title":"mm/damon/core: always put unsuccessfully committed target pids","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-72178","datePublished":"2026-08-15T05:53:42.238Z","dateReserved":"2026-08-09T03:40:39.910Z","dateUpdated":"2026-08-17T05:09:40.842Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-15 06:21:36","lastModifiedDate":"2026-08-17 06:18:18","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"72178","Ordinal":"1","Title":"mm/damon/core: always put unsuccessfully committed target pids","CVE":"CVE-2026-72178","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"72178","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/core: always put unsuccessfully committed target pids\n\ndamon_commit_target() puts and gets the destination and the source target\npids.  It puts the destination target pid because it will be overwritten\nby the source target pid.  It gets the source pid because the caller is\nsupposed to eventually put the pids.  In more detail, the caller will call\ndamon_destroy_ctx() after damon_commit_ctx() to destroy the entire source\ncontext.  And in this case, [f]vaddr operation set's cleanup_target()\ncallback will put the pids.\n\nThe commit operation is made at the context level.  The operation can fail\nin multiple places including in the middle and after the targets commit\noperations.  For any such failures, immediately the error is returned to\nthe damon_commit_ctx() caller.  If some or all of the source target pids\nwere committed to the destination during the unsuccessful context commit\nattempt, those pids should be put twice.\n\nThe source context will do the put operations using the above explained\nroutine.  However, let's suppose the destination context was not\noriginally using [f]vaddr operation set and the commit failed before the\nops of the source context is committed.  The destination does not have the\ncleanup_target() ops callback, so it cannot put the pids via the\ndamon_destroy_ctx().\n\nAs a result, the pids are leaked.  The issue in the real world would be\nnot very common.  The commit feature is for changing parameters of running\nDAMON context while inheriting internal status like the monitoring\nresults.  The monitoring results of a physical address range ain't have\nthings that are beneficial to be inherited to a virtual address ranges\nmonitoring.  So the problem-causing DAMON control would be not very common\nin the real world.  That said, it is a supported feature.  And\ndamon_commit_target() failure due to memory allocation is relatively\nrealistic [1] if there are a huge number of target regions.\n\nFix by putting the pids in the commit operation in case of the failures.\n\nThe issue was discovered [2] by Sashiko.","Type":"Description","Title":"mm/damon/core: always put unsuccessfully committed target pids"}]}}}