CVE-2026-74644

medium

Description

In the Linux kernel, the following vulnerability has been resolved: mm/damon/ops-common: putback folios on invalid migrate nid damon_pa_migrate() and damos_va_migrate() isolate folios into a local list and then call damon_migrate_pages(). When target_nid is invalid (including the scheme default NUMA_NO_NODE / -1), damon_migrate_pages() returns early without putting the folios back to the LRU. Callers then discard the list head while those folios remain isolated with an extra reference taken by folio_isolate_lru(). The pages stay off the LRU for as long as the mapping exists (anon active+inactive counts drop while RSS does not), and the leftover references can pin the pages after the mapping is gone. Put the folios back on the invalid-nid path so ignored migration requests still return them to the LRU.

References

https://git.kernel.org/stable/c/cfef454862b7d2776e0955b873dd59af6b47cfcb

https://git.kernel.org/stable/c/7001c0a1bc9018cd5b2b72ebebb216d738b2ec81

https://git.kernel.org/stable/c/5deb65c34e682e7c5f5df417a70e223e8fcc5f5a

https://git.kernel.org/stable/c/460181e4bb47a57776c64f0832c2096de8878cb3

Details

Source: Mitre, NVD

Published: 2026-08-22

Updated: 2026-08-23

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00206