CVE-2026-80956
Received Received - Intake

dm-pcache Segment Allocation Flaw in Linux Kernel

Vulnerability report for CVE-2026-80956, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: dm-pcache: only hand out initialized cache segments get_cache_segment() scans the segment map up to cache->n_segs, the physical device segment count, but cache_segs_init() only initializes the first cache_info->n_segs segments. A crafted image with cache_info->n_segs smaller than the device count leaves the remaining pcache_cache_segment structs zeroed (segment.data == NULL), and the allocator can hand one to cache_kset_close(), which writes through the returned segment's data pointer with no NULL check. Bound the allocator's search to cache_info->n_segs so only initialized segments are ever returned. A conforming cache sets n_segs equal to the device segment count, so this rejects nothing legitimate.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel's dm-pcache module involves a flaw where uninitialized cache segments could be handed out. The get_cache_segment() function scans segments up to the device's physical count, but only the first n_segs segments are initialized. This leaves remaining segments with null data pointers, which could lead to a write operation through a null pointer if such a segment is allocated.

Detection Guidance

This vulnerability is specific to the Linux kernel's dm-pcache module and requires kernel-level inspection. Detection involves checking kernel logs for related errors or verifying the dm-pcache module's behavior. Commands like dmesg | grep dm-pcache or checking /var/log/kern.log may reveal issues. No network-specific detection commands are applicable.

Impact Analysis

This vulnerability could allow an attacker to cause a denial of service or potentially execute arbitrary code by exploiting the null pointer dereference in the dm-pcache module. Systems using dm-pcache with crafted cache images may be vulnerable to crashes or unexpected behavior.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It is a low-level kernel memory corruption issue in the dm-pcache component that could lead to data corruption or crashes but does not involve unauthorized data access or disclosure.

Mitigation Strategies

Update the Linux kernel to a patched version where this vulnerability is resolved. If using a distribution kernel, apply vendor-provided updates. Avoid using dm-pcache with untrusted cache images until patched. Monitor kernel logs for dm-pcache related errors post-update.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80956. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart