Description
In the Linux kernel, the following vulnerability has been resolved:

dm-pcache: only hand out initialized cache segments

get_cache_segment() scans the segment map up to cache->n_segs, the
physical device segment count, but cache_segs_init() only initializes
the first cache_info->n_segs segments. A crafted image with
cache_info->n_segs smaller than the device count leaves the remaining
pcache_cache_segment structs zeroed (segment.data == NULL), and the
allocator can hand one to cache_kset_close(), which writes through the
returned segment's data pointer with no NULL check.

Bound the allocator's search to cache_info->n_segs so only initialized
segments are ever returned. A conforming cache sets n_segs equal to the
device segment count, so this rejects nothing legitimate.
Published: 2026-09-11
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel dm‑pcache driver contains a logic flaw that allows the allocator to return cache segment structures that have not been fully initialized. When a crafted dm‑cache image advertises fewer segments than the device actually holds, the remaining segment structs are left zeroed, with a NULL data pointer. Closing such a segment causes the driver to write through this NULL pointer, leading to a null‑pointer dereference that corrupts kernel memory. While this flaw does not guarantee arbitrary code execution, the memory corruption could disrupt kernel operation or be leveraged to elevate privileges if an attacker can supply a malicious dm‑cache image. The likely attack vector is the introduction of a malformed dm‑cache image; this inference is based on the description since the attack method is not explicitly stated.

Affected Systems

This flaw exists in the dm‑pcache component of the Linux kernel. Any kernel version released before is affected. No specific version list is supplied, so all unpatched kernel releases that enable dm‑pcache are potentially at risk.

Risk and Exploitability

The vulnerability is scored 4.4 on the CVSS scale, indicating low severity. Its EPSS score is less than 1%, showing a very low exploitation probability. It is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a malformed dm‑cache image and the target must have dm‑pcache enabled. Because the malicious image must be loaded by the kernel, the attack is limited to environments where such images can be introduced, such as container images or disk snapshots. The lack of a null check and the resultant kernel memory corruption make the bug dangerous when dm‑pcache is in use, but the overall threat remains modest due to the low EPSS and the need for privileged image creation. The attack vector is inferred from the requirement to supply a malicious dm‑cache image, as the description does not explicitly state the vector.

Generated by OpenCVE AI on September 21, 2026 at 03:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that contains the allocator search to the declared segment count.
  • If an immediate kernel update is not possible, unload or disable the dm‑pcache module to prevent uninitialized segments from being processed.
  • Ensure that any custom dm‑cache images created for the system have n_segs equal to the device’s segment count, and restrict image creation to trusted sources to avoid malformed images.

Generated by OpenCVE AI on September 21, 2026 at 03:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-824
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dm-pcache: only hand out initialized cache segments get_cache_segment() scans the segment map up to cache->n_segs, the physical device segment count, but cache_segs_init() only initializes the first cache_info->n_segs segments. A crafted image with cache_info->n_segs smaller than the device count leaves the remaining pcache_cache_segment structs zeroed (segment.data == NULL), and the allocator can hand one to cache_kset_close(), which writes through the returned segment's data pointer with no NULL check. Bound the allocator's search to cache_info->n_segs so only initialized segments are ever returned. A conforming cache sets n_segs equal to the device segment count, so this rejects nothing legitimate.
Title dm-pcache: only hand out initialized cache segments
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:42:24.541Z

Reserved: 2026-08-26T14:34:25.804Z

Link: CVE-2026-80956

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:01.410

Modified: 2026-09-11T20:19:01.410

Link: CVE-2026-80956

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:24Z

Links: CVE-2026-80956 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:15:09Z

Weaknesses
  • CWE-824

    Access of Uninitialized Pointer