CVE-2026-23142
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-23142 is a resource management vulnerability in the Linux kernel's DAMON (Data Access MONitor) sysfs-scheme subsystem, caused by incomplete cleanup of access_pattern/ subdirectories when a DAMOS-scheme sysfs directory setup fails. The flaw was published on February 14, 2026, and affects Linux kernel versions from 5.18 through multiple stable branches. Affected version ranges include 5.18–6.1.161, 6.2–6.6.121, 6.7–6.12.66, and 6.13–6.18.6, as well as release candidates for 6.19. It carries a CVSS v3.1 base score of 5.5 (Medium) (Feedly).

Technical details

The root cause is improper resource cleanup (CWE-459: Incomplete Cleanup / resource leak) in mm/damon/sysfs-scheme.c. When a DAMOS-scheme DAMON sysfs directory setup fails after the access_pattern/ directory has already been created, the kernel does not remove the subdirectories of access_pattern/, leaving orphaned sysfs entries and leaking the associated memory. The attack vector is local (AV:L), requires low privileges (PR:L), and no user interaction, making it triggerable by any unprivileged local user who can interact with the DAMON sysfs interface. Patches addressing the issue are available as multiple stable kernel commits (Kernel Patches).

Impact

Successful exploitation causes a denial-of-service condition: orphaned sysfs directories persist until system reboot, the DAMON sysfs interface becomes nearly non-functional, and kernel memory is leaked over time. There is no confidentiality or integrity impact — the vulnerability is limited to availability (A:H). Repeated triggering could accelerate memory exhaustion on long-running systems, potentially destabilizing the kernel (Feedly).

Mitigation and workarounds

Update the Linux kernel to one of the following patched versions based on your branch: 6.1.162 or later (for 5.18–6.1.x), 6.6.122 or later (for 6.2–6.6.x), 6.12.67 or later (for 6.7–6.12.x), or 6.18.7 or later (for 6.13+). As a workaround where patching is not immediately possible, restrict local user access to the DAMON sysfs interface (e.g., via filesystem permissions on /sys/kernel/mm/damon/) and monitor system memory for signs of gradual exhaustion. Oracle, SUSE, Red Hat, and Ubuntu have all issued advisories referencing this CVE (Feedly, Oracle Advisory, Ubuntu Advisory).

Community reactions

Multiple Linux distribution vendors — including Oracle, SUSE, Red Hat, and Ubuntu — have issued security advisories referencing CVE-2026-23142 as part of broader kernel update packages. Tenable's Nessus scanner has published multiple detection plugins (IDs 299216, 301875, 304219, 318847) for this vulnerability. Coverage has been limited to routine kernel vulnerability tracking with no notable researcher commentary or significant social media discussion (Oracle Advisory, Ubuntu Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management