Security Advisory

CVE-2022-48996

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-10-21 20:06:12
Last updated 2026-05-11 18:51:11
Assigner Linux
State PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: fix wrong empty schemes assumption under online tuning in damon_sysfs_set_schemes() Commit da87878010e5 ("mm/damon/sysfs: support online inputs update") made damon_sysfs_set_schemes() to be called for running DAMON context, which could have schemes. In the case, DAMON sysfs interface is supposed to update, remove, or add schemes to reflect the sysfs files. However, the code is assuming the DAMON context wouldnt have schemes at all, and therefore creates and adds new schemes. As a result, the code doesnt work as intended for online schemes tuning and could have more than expected memory footprint. The schemes are all in the DAMON context, so it doesnt leak the memory, though. Remove the wrong asssumption (the DAMON context wouldnt have schemes) in damon_sysfs_set_schemes() to fix the bug.