{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.19.13-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  mm/damon/stat: deallocate damon_call() failure leaking damon_ctx  damon_stat_start() always allocates the module's damon_ctx object (damon_stat_context).  Meanwhile, if damon_call() in the function fails, the damon_ctx object is not deallocated.  Hence, if the damon_call() is failed, and the user writes Y to “enabled” again, the previously allocated damon_ctx object is leaked.  This cannot simply be fixed by deallocating the damon_ctx object when damon_call() fails.  That's because damon_call() failure doesn't guarantee the kdamond main function, which accesses the damon_ctx object, is completely finished.  In other words, if damon_stat_start() deallocates the damon_ctx object after damon_call() failure, the not-yet-terminated kdamond could access the freed memory (use-after-free).  Fix the leak while avoiding the use-after-free by keeping returning damon_stat_start() without deallocating the damon_ctx object after damon_call() failure, but deallocating it when the function is invoked again and the kdamond is completely terminated.  If the kdamond is not yet terminated, simply return -EAGAIN, as the kdamond will soon be terminated.  The issue was discovered [1] by sashiko.",
  "id": "DEBIAN-CVE-2026-31652",
  "modified": "2026-09-14T16:47:29.708310928Z",
  "published": "2026-04-24T15:16:44.697Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-31652"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-31652"
  ]
}