Description
In the Linux kernel, the following vulnerability has been resolved:

dm-pcache: validate kset key_num and intra-segment bounds

Two more fields decoded from the cache device go unbounded. The kset
key_num drives cache_kset_crc() and the replay loop in cache_replay(),
the writeback worker and the GC worker, but only the magic and a
fixed-seed CRC are checked first, so a non-last kset whose key_num exceeds
the PCACHE_KSET_KEYS_MAX buffer reads past its end before the CRC compare.
A key's intra-segment offset and length in cache_key_decode() are taken
verbatim, so a key running past its segment is replayed into the cache
tree and the data CRC check and every later read hit then copy adjacent
persistent memory into the caller's bio -- an out-of-bounds read that
leaks to user space. Both fields are controlled by whoever supplies the
cache device (CAP_SYS_ADMIN); the CRC seed is public.

Add kset_onmedia_valid() to bound key_num before any kset read, and
reject a key whose offset plus length, computed in 64 bits, exceeds the
segment data_size. Valid metadata is unaffected.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Kernel
AI Analysis

Impact

The dm‑pcache subsystem contains a flaw where the kset key_num field and the intra‑segment offset and length are not bounded before use. A malicious cache device crafted by a user with CAP_SYS_ADMIN causes the kernel to read past the end of the key bio. This out‑of‑bounds read can leak any data that resides in the kernel’s memory space, making it a high‑severity information‑disclosure vulnerability (CWE‑125).

Affected Systems

All Linux kernel releases that include the dm‑pcache code without the bounds‑check patch are affected. The CNA only lists generic Linux kernel entries, so any distribution relying on an unpatched kernel may be vulnerable; no specific version range is provided, and thus all kernels containing this code should be treated as potentially impacted until the fix is applied.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity level, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV. The likely attack vector is a local user possessing CAP_SYS_ADMIN who supplies a malicious cache device to the kernel; the need for local privileged access limits the threat surface to compromised or trusted accounts.

Generated by OpenCVE AI on September 21, 2026 at 03:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel release that contains the dm‑pcache bounds‑check patch.
  • If a patched kernel is unavailable, unload or disable the dm‑pcache kernel module until the update can be applied.
  • Restrict the CAP_SYS_ADMIN capability to trusted administrators so that only authorized users can create cache devices that might trigger the vulnerability.

Generated by OpenCVE AI on September 21, 2026 at 03:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 2.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 2.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate kset key_num and intra-segment bounds Two more fields decoded from the cache device go unbounded. The kset key_num drives cache_kset_crc() and the replay loop in cache_replay(), the writeback worker and the GC worker, but only the magic and a fixed-seed CRC are checked first, so a non-last kset whose key_num exceeds the PCACHE_KSET_KEYS_MAX buffer reads past its end before the CRC compare. A key's intra-segment offset and length in cache_key_decode() are taken verbatim, so a key running past its segment is replayed into the cache tree and the data CRC check and every later read hit then copy adjacent persistent memory into the caller's bio -- an out-of-bounds read that leaks to user space. Both fields are controlled by whoever supplies the cache device (CAP_SYS_ADMIN); the CRC seed is public. Add kset_onmedia_valid() to bound key_num before any kset read, and reject a key whose offset plus length, computed in 64 bits, exceeds the segment data_size. Valid metadata is unaffected.
Title dm-pcache: validate kset key_num and intra-segment bounds
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:28:32.873Z

Reserved: 2026-08-26T14:34:25.809Z

Link: CVE-2026-80961

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:01.980

Modified: 2026-09-13T07:17:03.070

Link: CVE-2026-80961

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:27Z

Links: CVE-2026-80961 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:15:09Z

Weaknesses