Description
In the Linux kernel, the following vulnerability has been resolved:

dm-pcache: validate seg_id fields from persistent memory

cache_pos_decode(), cache_key_decode() and the last-kset branches of
cache_replay(), the writeback worker and the GC worker take a cache
segment id from the cache device metadata and index cache->segments[]
with it without checking it against cache->n_segs. That metadata is only
CRC-protected with a fixed public seed, so whoever supplies the cache
device on a table load (CAP_SYS_ADMIN) controls the id; an out-of-range
value forms a wild pcache_cache_segment pointer that is dereferenced and
written through -- an out-of-bounds read and write driven by on-disk data.

Add cache_seg_id_valid() and reject an out-of-range id at each decode
site, failing the operation with -EIO instead of indexing past the array.
Bound the id against the initialized-segment count (cache_info.n_segs)
rather than the physical device total. A forged cache_info.n_segs below
seg_num otherwise leaves segments[cache_info.n_segs..seg_num) as zeroed
structs whose data pointer is NULL, so a forged id in that window would
still be dereferenced. A later patch guarantees cache_info.n_segs <=
seg_num, and a driver-created cache sets the two equal, so valid images
are unaffected.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds read/write that can corrupt kernel memory and enable privilege escalation
Action: Apply Patch
AI Analysis

Impact

The flaw exists in the Linux DM PCACHE subsystem, where the kernel accepts cache segment identifiers from persistent metadata without validating them against the number of initialized segments. An attacker with CAP_SYS_ADMIN who supplies a malicious cache device can cause the kernel to index past the end of the segments array, resulting in out-of-bounds reads and writes. This can corrupt kernel memory, leading to denial of service or privilege escalation.

Affected Systems

All Linux kernel implementations that include the DM PCACHE module before the patch that adds cache_seg_id_valid() are affected. Systems that have not yet applied the kernel update are vulnerable.

Risk and Exploitability

The CVSS base score of 7.8 indicates high severity, while the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires CAP_SYS_ADMIN privileges to load a cache device, limiting the pool of capable attackers.

Generated by OpenCVE AI on September 20, 2026 at 00:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the Linux kernel patch that introduces cache_seg_id_valid() checks (e.g., applies the commits referenced in the advisory).
  • If the patch cannot be applied immediately, restrict CAP_SYS_ADMIN privileges for processes that load DM PCACHE cache devices or limit access to the cache device files to trusted users only.
  • Validate any existing cache device images to ensure their seg_id values are within bounds, and regenerate or rebuild caches that contain forged metadata.

Generated by OpenCVE AI on September 20, 2026 at 00:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-126

Sat, 19 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-126

Sat, 19 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-126

Sat, 19 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-126

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate seg_id fields from persistent memory cache_pos_decode(), cache_key_decode() and the last-kset branches of cache_replay(), the writeback worker and the GC worker take a cache segment id from the cache device metadata and index cache->segments[] with it without checking it against cache->n_segs. That metadata is only CRC-protected with a fixed public seed, so whoever supplies the cache device on a table load (CAP_SYS_ADMIN) controls the id; an out-of-range value forms a wild pcache_cache_segment pointer that is dereferenced and written through -- an out-of-bounds read and write driven by on-disk data. Add cache_seg_id_valid() and reject an out-of-range id at each decode site, failing the operation with -EIO instead of indexing past the array. Bound the id against the initialized-segment count (cache_info.n_segs) rather than the physical device total. A forged cache_info.n_segs below seg_num otherwise leaves segments[cache_info.n_segs..seg_num) as zeroed structs whose data pointer is NULL, so a forged id in that window would still be dereferenced. A later patch guarantees cache_info.n_segs <= seg_num, and a driver-created cache sets the two equal, so valid images are unaffected.
Title dm-pcache: validate seg_id fields from persistent memory
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:56:31.622Z

Reserved: 2026-09-17T16:02:15.092Z

Link: CVE-2026-93201

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:16.403

Modified: 2026-09-18T18:18:24.903

Link: CVE-2026-93201

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:45:16Z

Weaknesses

No weakness.