7.8

CVE-2026-80961

dm-pcache: validate kset key_num and intra-segment bounds

In the Linux kernel, the following vulnerability has been resolved:

dm-pcache: validate kset key_num and intra-segment bounds

Two more fields decoded from the cache device go unbounded. The kset
key_num drives cache_kset_crc() and the replay loop in cache_replay(),
the writeback worker and the GC worker, but only the magic and a
fixed-seed CRC are checked first, so a non-last kset whose key_num exceeds
the PCACHE_KSET_KEYS_MAX buffer reads past its end before the CRC compare.
A key's intra-segment offset and length in cache_key_decode() are taken
verbatim, so a key running past its segment is replayed into the cache
tree and the data CRC check and every later read hit then copy adjacent
persistent memory into the caller's bio -- an out-of-bounds read that
leaks to user space. Both fields are controlled by whoever supplies the
cache device (CAP_SYS_ADMIN); the CRC seed is public.

Add kset_onmedia_valid() to bound key_num before any kset read, and
reject a key whose offset plus length, computed in 64 bits, exceeds the
segment data_size. Valid metadata is unaffected.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0
Version < d8caf96040a06096276ab72f5e1e8547c014c564
Status affected
Version 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0
Version < 5ac38f4b4862fad6e7270fde5c3356a822ce74ca
Status affected
Version 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0
Version < f11deb032fd84081e7831cffcba895d893054a22
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.18
Status affected
Version 0
Version < 6.18
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.057
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/d8caf96040a06096276ab72f5e1e8547c014c564
https://git.kernel.org/stable/c/5ac38f4b4862fad6e7270fde5c3356a822ce74ca
https://git.kernel.org/stable/c/f11deb032fd84081e7831cffcba895d893054a22