CVE-2026-74644

Summary

In the Linux kernel, the following vulnerability has been resolved:

mm/damon/ops-common: putback folios on invalid migrate nid

damon_pa_migrate() and damos_va_migrate() isolate folios into a local list and then call damon_migrate_pages(). When target_nid is invalid (including the scheme default NUMA_NO_NODE / -1), damon_migrate_pages() returns early without putting the folios back to the LRU.

Callers then discard the list head while those folios remain isolated with an extra reference taken by folio_isolate_lru(). The pages stay off the LRU for as long as the mapping exists (anon active+inactive counts drop while RSS does not), and the leftover references can pin the pages after the mapping is gone.

Put the folios back on the invalid-nid path so ignored migration requests still return them to the LRU.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux7c303fa1f311aadc17fa82b7bbf776412adf45de < 7001c0a1bc9018cd5b2b72ebebb216d738b2ec81affected
LinuxLinux7e6c3130690a01076efdf45aa02ba5d5c16849a0 < 460181e4bb47a57776c64f0832c2096de8878cb3affected
LinuxLinux7e6c3130690a01076efdf45aa02ba5d5c16849a0 < cfef454862b7d2776e0955b873dd59af6b47cfcbaffected
LinuxLinux7e6c3130690a01076efdf45aa02ba5d5c16849a0 < 5deb65c34e682e7c5f5df417a70e223e8fcc5f5aaffected
LinuxLinux9d0c2d15aff96746f99a7c97221bb8ce5b62db19affected
LinuxLinux6.12.44 < 6.12.105affected
LinuxLinux6.16.4 < 6.17affected
LinuxLinux6.17affected
LinuxLinux0 < 6.17unaffected
LinuxLinux6.12.105 <= 6.12.*unaffected
LinuxLinux6.18.45 <= 6.18.*unaffected
LinuxLinux7.1.9 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References