{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.5-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  samples/damon/mtier: fail early if address range parameters are invalid  The comment on top of `struct damon_region` clearly says that      For any use case, @ar should be non-zero positive size.  which is now verified in damon_verify_new_region() if the kernel is built with DAMON_DEBUG_SANITY.  The WARN_ONCE() can be triggered if the mtier sample module is enabled before node{0,1}_{start,end}_addr have been properly initialized, which is obviously not good.   ------------[ cut here ]------------  start 0 \u003e= end 0  WARNING: mm/damon/core.c:217 at damon_new_region+0xf4/0x118, CPU#59: bash/341468  Call trace:   damon_new_region+0xf4/0x118 (P)   damon_set_regions+0xfc/0x3c0   damon_sample_mtier_build_ctx+0xe8/0x3a8   damon_sample_mtier_start+0x1c/0x90   damon_sample_mtier_enable_store+0x98/0xb0   param_attr_store+0xb4/0x128   module_attr_store+0x2c/0x50   sysfs_kf_write+0x58/0x90   kernfs_fop_write_iter+0x16c/0x238   vfs_write+0x2c0/0x370   ksys_write+0x74/0x118   __arm64_sys_write+0x24/0x38   invoke_syscall+0xa8/0x118   el0_svc_common.constprop.0+0x48/0xf0   do_el0_svc+0x24/0x38   el0_svc+0x54/0x370   el0t_64_sync_handler+0xa0/0xe8   el0t_64_sync+0x1ac/0x1b0  ---[ end trace 0000000000000000 ]---  Note that the same issue can happen if detect_node_addresses is true, and node 0 or 1 is memoryless.  Fix it together by checking the validity of parameters right before damon_new_region() and fail early if they're invalid.",
  "id": "DEBIAN-CVE-2026-80592",
  "modified": "2026-09-14T16:47:48.822837804Z",
  "published": "2026-08-28T08:16:42.830Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-80592"
    }
  ],
  "upstream": [
    "CVE-2026-80592"
  ]
}