Description
In the Linux kernel, the following vulnerability has been resolved:

dm-pcache: validate on-media seg_num against the cache device size

seg_num is read from the crc32c-only superblock, so whoever supplies the
cache device on a table load (CAP_SYS_ADMIN) controls it. It sizes
cache->segments[] and is the value every later on-media segment id is
bounded against, yet it is never checked against the device. Because
cache_dev->mapping is the direct map of the pmem, CACHE_DEV_SEGMENT() for
a segment id past the device resolves to ordinary kernel memory beyond
the mapping; a new-cache init reaching such an id has cache_seg_init() ->
cache_dev_zero_range() memset() 12 KiB over that memory -- an
out-of-bounds write into the kernel heap at table load. A zero seg_num
makes the segment allocations ZERO_SIZE_PTR.

Reject a seg_num that is zero, larger than the device can hold, or larger
than PCACHE_CACHE_SEGS_MAX before it is used.
Published: 2026-09-11
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Update Kernel
AI Analysis

Impact

During a device‑mapper table load, a privileged user supplies a cache device whose superblock contains a value called seg_num. That value is used to size an array that bounds future segment identifiers, but it is not validated against the device’s actual capacity. When a segment id beyond the mapping range is accessed, the kernel performs a 12 KiB memset that writes past the end of the mapped device into arbitrary kernel heap memory. This out‑of‑bounds write (CWE‑787) corrupts kernel memory and can lead to arbitrary code execution with root privileges.

Affected Systems

All Linux kernel builds that include the dm‑pcache module are potentially impacted; no specific release versions are listed in the advisory. The flaw exists in every distribution that ships a kernel version containing the affected pcache code path.

Risk and Exploitability

The CVSS score of 5.7 indicates medium severity, while the EPSS score of < 1% suggests a low probability of exploitation. The bug requires CAP_SYS_ADMIN and can only be triggered locally. If exploited, heap corruption can lead to privilege escalation to root. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 21, 2026 at 02:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the patch referenced in the advisory
  • Ifpcache module or remove the privilege of CAP_SYS_ADMIN for the affected user.
  • Monitor system logs for signs of memory corruption or unrelated kernel crashes.

Generated by OpenCVE AI on September 21, 2026 at 02:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate on-media seg_num against the cache device size seg_num is read from the crc32c-only superblock, so whoever supplies the cache device on a table load (CAP_SYS_ADMIN) controls it. It sizes cache->segments[] and is the value every later on-media segment id is bounded against, yet it is never checked against the device. Because cache_dev->mapping is the direct map of the pmem, CACHE_DEV_SEGMENT() for a segment id past the device resolves to ordinary kernel memory beyond the mapping; a new-cache init reaching such an id has cache_seg_init() -> cache_dev_zero_range() memset() 12 KiB over that memory -- an out-of-bounds write into the kernel heap at table load. A zero seg_num makes the segment allocations ZERO_SIZE_PTR. Reject a seg_num that is zero, larger than the device can hold, or larger than PCACHE_CACHE_SEGS_MAX before it is used.
Title dm-pcache: validate on-media seg_num against the cache device size
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:42:27.182Z

Reserved: 2026-08-26T14:34:25.809Z

Link: CVE-2026-80960

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:01.863

Modified: 2026-09-11T20:19:01.863

Link: CVE-2026-80960

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:27Z

Links: CVE-2026-80960 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:45:08Z

Weaknesses