-

CVE-2026-80960

dm-pcache: validate on-media seg_num against the cache device size

In the Linux kernel, the following vulnerability has been resolved:

dm-pcache: validate on-media seg_num against the cache device size

seg_num is read from the crc32c-only superblock, so whoever supplies the
cache device on a table load (CAP_SYS_ADMIN) controls it. It sizes
cache->segments[] and is the value every later on-media segment id is
bounded against, yet it is never checked against the device. Because
cache_dev->mapping is the direct map of the pmem, CACHE_DEV_SEGMENT() for
a segment id past the device resolves to ordinary kernel memory beyond
the mapping; a new-cache init reaching such an id has cache_seg_init() ->
cache_dev_zero_range() memset() 12 KiB over that memory -- an
out-of-bounds write into the kernel heap at table load. A zero seg_num
makes the segment allocations ZERO_SIZE_PTR.

Reject a seg_num that is zero, larger than the device can hold, or larger
than PCACHE_CACHE_SEGS_MAX before it is used.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0
Version < 91b93fe5cf4d62d5ecc642a6c8f15a3c11b00e3c
Status affected
Version 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0
Version < e889c0ee81165fc90aad2979b51f930f77895703
Status affected
Version 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0
Version < 62d92e45abe9e087370f9fc5d876b95673aced34
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.18
Status affected
Version 0
Version < 6.18
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.097
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/91b93fe5cf4d62d5ecc642a6c8f15a3c11b00e3c
https://git.kernel.org/stable/c/e889c0ee81165fc90aad2979b51f930f77895703
https://git.kernel.org/stable/c/62d92e45abe9e087370f9fc5d876b95673aced34