Description
In the Linux kernel, the following vulnerability has been resolved:

dm-pcache: bound the persisted tail-position offset

cache_pos_decode() takes the persisted key_tail and dirty_tail seg_off from
the cache device and addresses within the segment with it. A seg_off at or
past the segment data_size, controllable by whoever supplies the device
(CAP_SYS_ADMIN), reads past the segment data.

Reject a decoded seg_off that is not below the segment data_size.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds Read
Action: Patch
AI Analysis

Impact

In the Linux kernel, the device‑mapper cache (dm‑pcache) component decodes offsets representing the persisted tail position. The function cache_pos_decode() takes the persisted key_tail and dirty_tail seg_off from the cache device and uses them to calculate addresses within the segment. When a seg_off at or past the segment data_size, controllable by anyone who supplies the device (CAP_SYS_ADMIN), is decoded, the driver reads past the end of the segment data. This out-of-bounds read can expose portions of kernel memory to a privileged user. The weakness corresponds to CWE‑125.

Affected Systems

All Linux systems that include the dm‑pcache driver in the kernel are affected. The vulnerability exists in any kernel build that loads dm‑pcache without the recent bounds‑check patch. Users with capabilities to supply CAP_SYS_ADMIN or equivalent root privileges are the ones who can trigger the fault.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity local‑privileged information‑leak scenario requiring a crafted device for the dm‑pcache driver. The EPSS score of < 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Consequently, the threat is primarily a local‑privileged information‑leak scenario for systems that expose dm‑pcache devices to privileged users.

Generated by OpenCVE AI on September 21, 2026 at 02:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that incorporates the dm‑pcache bounds‑check patch.
  • Remove or restrict or modify dm‑pcache device data.
  • Limit access to dm‑pcache device nodes so only trusted users can interact with the driver.

Generated by OpenCVE AI on September 21, 2026 at 02:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dm-pcache: bound the persisted tail-position offset cache_pos_decode() takes the persisted key_tail and dirty_tail seg_off from the cache device and addresses within the segment with it. A seg_off at or past the segment data_size, controllable by whoever supplies the device (CAP_SYS_ADMIN), reads past the segment data. Reject a decoded seg_off that is not below the segment data_size.
Title dm-pcache: bound the persisted tail-position offset
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:28:31.649Z

Reserved: 2026-08-26T14:34:25.809Z

Link: CVE-2026-80959

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:01.750

Modified: 2026-09-13T07:17:02.943

Link: CVE-2026-80959

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:26Z

Links: CVE-2026-80959 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:45:08Z

Weaknesses