CVE-2025-39909 Details
Description
In the Linux kernel, the following vulnerability has been resolved: mm/damon/lru_sort: avoid divide-by-zero in damon_lru_sort_apply_parameters() Patch series "mm/damon: avoid divide-by-zero in DAMON module's parameters application". DAMON's RECLAIM and LRU_SORT modules perform no validation on user-configured parameters during application, which may lead to division-by-zero errors. Avoid the divide-by-zero by adding validation checks when DAMON modules attempt to apply the parameters. This patch (of 2): During the calculation of 'hot_thres' and 'cold_thres', either 'sample_interval' or 'aggr_interval' is used as the divisor, which may lead to division-by-zero errors. Fix it by directly returning -EINVAL when such a case occurs. Additionally, since 'aggr_interval' is already required to be set no smaller than 'sample_interval' in damon_set_attrs(), only the case where 'sample_interval' is zero needs to be checked.
A vulnerability in the Linux kernel's DAMON module, specifically within the LRU_SORT and RECLAIM functionalities, has been addressed. The issue stemmed from a lack of validation on user-defined parameters, which could lead to division-by-zero errors. This vulnerability was particularly relevant when the 'sample_interval' parameter was set to zero, as it could cause the calculations for 'hot_thres' and 'cold_thres' to fail, potentially disrupting the DAMON module's operations.
Users can update to the latest version of the Linux kernel where this vulnerability has been patched. Instructions for downloading the updated kernel can be found on the official Linux kernel website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/326a4b3750c71af3f3c52399ec4dbe33b6da4c26 | kernel.org | Patch |
| https://git.kernel.org/stable/c/711f19dfd783ffb37ca4324388b9c4cb87e71363 | kernel.org | Patch |
| https://git.kernel.org/stable/c/74e391f7da7d9d5235a3cca88ee9fc18f720c75b | kernel.org | Patch |
| https://git.kernel.org/stable/c/7bb675c9f0257840d33e5d1337d7e3afdd74a6bf | kernel.org | Patch |
| https://git.kernel.org/stable/c/af0ae62b935317bed1a1361c8c9579db9d300e70 | kernel.org | Patch |
| https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html | CVE | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-369 | Divide By Zero | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.0, < 6.1.153 >= 6.2, < 6.6.107 >= 6.7, < 6.12.48 >= 6.13, < 6.16.8 6.17 rc1 6.17 rc2 6.17 rc3 6.17 rc4 6.17 rc5 |
CPE
Remediation
| |
| debian debian linux | 11.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jan 16, 2026 | Initial Analysis | [email protected] |
| Nov 3, 2025 | CVE Modified | CVE |
| Oct 1, 2025 | New CVE Received | kernel.org |