Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-68164

Published Aug 10, 2026 EPSS 0.21% (12th pctl)

Overview

CVE-2026-68164 is a known-severity vulnerability. It was published on August 10, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

mm/damon/core: disallow overlapping input ranges for damon_set_regions()

damon_set_regions() assumes the input ranges are sorted by the address and

don't overlap each other. Hence the assumption was initially to be

explicitly validated. But commit 97d482f4592f ("mm/damon/sysfs: reuse

damon_set_regions() for regions setting") has mistakenly removed the

validation.

This can make DAMON behave in unexpected ways. At the best, the

monitoring results snapshot will just look weird since there will be

overlapping regions. DAMOS will also work weirdly, applying the same

action multiple times for overlapping regions, and make DAMOS quota weird.

More seriously, depending on the setup and regions updates sequence,

negative size regions can be made. It will trigger WARN_ONCE() if the

kernel is built with CONFIG_DAMON_DEBUG_SANITY=y. Depending on the

monitoring results, the negative size region can further trigger division

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-68164?

CVE-2026-68164 is a known-severity vulnerability. It was published on August 10, 2026.

How severe is CVE-2026-68164?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-68164?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-68164?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-68164 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.