Description
In the Linux kernel, the following vulnerability has been resolved:

dm-stats: fix a crash if allocation of per-cpu data fails

If "dm_kvzalloc(percpu_alloc_size, cpu_to_node(cpu))" fails, the code
jumps to the "out" label and calls dm_stat_free. dm_stat_free does
"for_each_possible_cpu(cpu) { dm_kvfree(s->stat_percpu[cpu][0].histogram,
s->histogram_alloc_size);", which crashes with NULL pointer dereference
if s->stat_percpu[cpu] is NULL.

This commit fixes the bug by testing s->stat_percpu[cpu] for NULL before
using it.
Published: 2026-09-11
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Crash)
Action: Patch
AI Analysis

Impact

A NULL pointer dereference occurs in the device a per‑CPU pointer, causing a flaw is a classic example of CWE‑476 and results in a local denial of service. The likely attack vector requires an attacker to trigger the per‑CPU allocation failure or otherwise influence kernel memory, typically requiring elevated privileges or a defect in scheduling that forces the allocation to fail. Modest impact on system availability, while the EPSS of <1% shows a very low probability of exploitation in the wild. The flaw is not listed in the would generally require local privileged conditions; once triggered, it leads to a kernel crash that can only be remedied by rebooting. The recent patch introduces a NULL check that fully mitigates the issue.

Affected Systems

All Linux kernel releases that do not include the commit identified in the referenced URLs are affected. The vulnerability applies to generic Linux distributions such as Red Hat, SUSE, Debian, or any vendor that ships the upstream kernel without the patch. Administrators should verify whether their kernel version predates the commit id 0c8f7870ed3ebd512f090d7714cc2c556b9e5c75 and apply the update if necessary.

Risk and Exploitability

The CVSS score of 4.1 indicates moderate severity. The EPSS score of <1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not present in CISA’s KEV catalog, further indicating limited threat surface. A local privileged attacker who can force a per‑CPU allocation failure could trigger the kernel crash. The fix prevents the NULL pointer dereference that previously caused the crash.

Generated by OpenCVE AI on September 21, 2026 at 03:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that contains the dm‑stats NULL check fix referenced by the commit URLs
  • Reboot the system after the kernel update to ensure the new code is active
  • If device‑mapper statistics are not required, disable the dm‑stats feature or restrict access to reduce the attack surface

Generated by OpenCVE AI on September 21, 2026 at 03:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dm-stats: fix a crash if allocation of per-cpu data fails If "dm_kvzalloc(percpu_alloc_size, cpu_to_node(cpu))" fails, the code jumps to the "out" label and calls dm_stat_free. dm_stat_free does "for_each_possible_cpu(cpu) { dm_kvfree(s->stat_percpu[cpu][0].histogram, s->histogram_alloc_size);", which crashes with NULL pointer dereference if s->stat_percpu[cpu] is NULL. This commit fixes the bug by testing s->stat_percpu[cpu] for NULL before using it.
Title dm-stats: fix a crash if allocation of per-cpu data fails
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:09.674Z

Reserved: 2026-08-26T14:34:25.810Z

Link: CVE-2026-80963

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:02.220

Modified: 2026-09-14T13:18:50.883

Link: CVE-2026-80963

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:29Z

Links: CVE-2026-80963 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:15:09Z

Weaknesses