Home

Description

In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: initialize damo_filter->list from damos_new_filter() damos_new_filter() is not initializing the list field of newly allocated filter object. However, DAMON sysfs interface and DAMON_RECLAIM are not initializing it after calling damos_new_filter(). As a result, accessing uninitialized memory is possible. Actually, adding multiple DAMOS filters via DAMON sysfs interface caused NULL pointer dereferencing. Initialize the field just after the allocation from damos_new_filter().

PUBLISHED Reserved 2025-10-04 | Published 2025-10-04 | Updated 2025-10-04 | Assigner Linux

Product status

Default status
unaffected

98def236f63c66629fb6b2d4b69cecffc5b46539 before da7beebb49c643cd03c54447ed66595936a7a1ce
affected

98def236f63c66629fb6b2d4b69cecffc5b46539 before 5f1fc67f2cb8d3035d3acd273b48b97835af8afd
affected

Default status
affected

6.3
affected

Any version before 6.3
unaffected

6.4.11
unaffected

6.5
unaffected

References

git.kernel.org/...c/da7beebb49c643cd03c54447ed66595936a7a1ce

git.kernel.org/...c/5f1fc67f2cb8d3035d3acd273b48b97835af8afd

cve.org (CVE-2023-53555)

nvd.nist.gov (CVE-2023-53555)

Download JSON