7.1

CVE-2026-80958

dm-pcache: clamp the tail kset read to the segment data region

In the Linux kernel, the following vulnerability has been resolved:

dm-pcache: clamp the tail kset read to the segment data region

The tail-kset read in cache_replay(), the writeback worker and the GC
worker bounds its length by PCACHE_SEG_SIZE - seg_off, the raw segment
size rather than the data region. A tail near the segment end reads past
the segment data into the following control area.

Clamp the read to cache_seg_remain(), the data region.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0
Version < 2cd9776fe3f2d88ec22c36d3c8ba09fbf9d5500c
Status affected
Version 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0
Version < 1ab55354368d071ebaee4d8c82313955eab65a04
Status affected
Version 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0
Version < becf07e2b0053027495ecd671b1f82fb2e615f68
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.18
Status affected
Version 0
Version < 6.18
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.024
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/2cd9776fe3f2d88ec22c36d3c8ba09fbf9d5500c
https://git.kernel.org/stable/c/1ab55354368d071ebaee4d8c82313955eab65a04
https://git.kernel.org/stable/c/becf07e2b0053027495ecd671b1f82fb2e615f68