Description
In the Linux kernel, the following vulnerability has been resolved:

dm-pcache: validate geometry fields from on-disk cache_info

cache_segs_init() iterates cache_info->n_segs times indexing
cache->segments[], which is sized to the cache device geometry, and
get_seg_id() takes each segment id from the on-media cache_info and the
per-segment next_seg link. Both come from cache device metadata that is
only CRC-protected with a fixed public seed, so whoever supplies the
cache device on a table load (CAP_SYS_ADMIN) controls them: an oversized
n_segs or an out-of-range id drives an out-of-bounds access of
cache->segments[] and a wild CACHE_DEV_SEGMENT() pointer into the device
mapping -- an out-of-bounds read and write from on-disk data.

Reject an n_segs that exceeds the device segment count and a segment id
that is out of range before either is used. Valid metadata is unaffected.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-Bounds Read/Write
Action: Patch
AI Analysis

Impact

The vulnerability arises when the dm‑pcache driver processes on‑disk metadata without proper bounds validation. When a cache device is loaded, the code reads the number of segments (n_segs) and the segment IDs from the metadata. If an attacker supplies an n_segs larger than the actual device segment count or a segment ID that falls outside the valid range, the driver accesses beyond the bounds of the cache->segments array, causing out‑of‑bounds reads and writes that can corrupt kernel memory. This memory corruption can lead to integrity compromise, privilege escalation, or a system crash, severely impacting confidentiality, integrity, and availability.

Affected Systems

No specific affected kernel version range is provided in the CVE data. The vulnerability is present in any Linux kernel that includes the dm‑pcache driver and has not applied the patch that validates cache geometry metadata on load. All systems that use dm‑pcache are potentially vulnerable until updated or the driver is disabled.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. The EPSS score of < 1% and the absence of a KEV listing suggest the likelihood of current exploitation is low. The exploit requires local capability to create or load a dm‑pcache table, so the attack vector is local. Vulnerable systems are those with dm‑pcache enabled; the potential impact includes memory corruption that can elevate privileges, corrupt data, or cause denial of service.

Generated by OpenCVE AI on September 21, 2026 at 03:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that includes the patch for dm‑pcache geometry validation.
  • If you cannot upgrade immediately, unload or disable the dm‑pcache module and remove any dm‑pcache tables from the system configuration.
  • Restrict CAP_SYS_ADMIN privileges to trusted administrators and audit table load events to detect malicious activity.

Generated by OpenCVE AI on September 21, 2026 at 03:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate geometry fields from on-disk cache_info cache_segs_init() iterates cache_info->n_segs times indexing cache->segments[], which is sized to the cache device geometry, and get_seg_id() takes each segment id from the on-media cache_info and the per-segment next_seg link. Both come from cache device metadata that is only CRC-protected with a fixed public seed, so whoever supplies the cache device on a table load (CAP_SYS_ADMIN) controls them: an oversized n_segs or an out-of-range id drives an out-of-bounds access of cache->segments[] and a wild CACHE_DEV_SEGMENT() pointer into the device mapping -- an out-of-bounds read and write from on-disk data. Reject an n_segs that exceeds the device segment count and a segment id that is out of range before either is used. Valid metadata is unaffected.
Title dm-pcache: validate geometry fields from on-disk cache_info
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:28:34.108Z

Reserved: 2026-08-26T14:34:25.809Z

Link: CVE-2026-80962

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:02.100

Modified: 2026-09-13T07:17:03.200

Link: CVE-2026-80962

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:28Z

Links: CVE-2026-80962 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:45:08Z

Weaknesses