Description
In the Linux kernel, the following vulnerability has been resolved:

dm-pcache: clamp the tail kset read to the segment data region

The tail-kset read in cache_replay(), the writeback worker and the GC
worker bounds its length by PCACHE_SEG_SIZE - seg_off, the raw segment
size rather than the data region. A tail near the segment end reads past
the segment data into the following control area.

Clamp the read to cache_seg_remain(), the data region.
Published: 2026-09-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The flaw occurs in the dm-pcache component of the Linux kernel where tail‑kset reads in cache_replay(), the writeback worker, and the GC worker were bounded by the raw segment size instead of the data region. A tail read near the end of a segment can therefore access memory beyond the data area and into the subsequent control area. This off‑by‑one read permits an attacker to read arbitrary kernel memory contents located past the segment data, thereby leaking sensitive information such as process data, credentials, or cryptographic keys. The weakness is a classic buffer overread (CWE-125).

Affected Systems

All Linux kernel builds that enable the dm-pcache device are vulnerable until the kernel patch that clamps the tail read to the data region is applied. No specific kernel version is listed in the advisory, so every unpatched kernel containing the affected code path is regarded as affected. It is inferred that dm-pcache exists in many Linux distributions.

Risk and Exploitability

The advisory reports a CVSS score of 7.1, indicating a high severity scenario. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or partially local through a user who can interact with a dm-pcache device, as the flaw does not provide remote code execution or privilege escalation. Nevertheless, the ability to read arbitrary kernel memory could lead to sensitive data exposure, and the risk remains non‑negligible because kernel memory is typically protected and not normally exposed to users.

Generated by OpenCVE AI on September 21, 2026 at 02:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that clamps the tail read to the data region.
  • If the patch cannot be applied, unload or disable the dm-pcache module to eliminate the vulnerable code path.
  • If disabling the module is not an option, restrict access to dm-pcache devices to privileged users only or configure policies that prevent untrusted users from interacting with dm-pcache devices.

Generated by OpenCVE AI on September 21, 2026 at 02:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dm-pcache: clamp the tail kset read to the segment data region The tail-kset read in cache_replay(), the writeback worker and the GC worker bounds its length by PCACHE_SEG_SIZE - seg_off, the raw segment size rather than the data region. A tail near the segment end reads past the segment data into the following control area. Clamp the read to cache_seg_remain(), the data region.
Title dm-pcache: clamp the tail kset read to the segment data region
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:28:30.422Z

Reserved: 2026-08-26T14:34:25.809Z

Link: CVE-2026-80958

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:01.637

Modified: 2026-09-13T07:17:02.823

Link: CVE-2026-80958

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:25Z

Links: CVE-2026-80958 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:45:08Z

Weaknesses