Executive brief
The Linux kernel's dm-pcache (device-mapper persistent cache) component fails to validate persisted tail-position offsets, allowing an administrator with device configuration privileges to craft a malicious cache device that triggers an out-of-bounds memory read. This could leak sensitive kernel memory or crash the system, affecting any environment using dm-pcache for caching.
Technical details
The vulnerability is an out-of-bounds read in the dm-pcache module's cache_pos_decode() function. The function reads persisted seg_off (segment offset) values from the cache device without validating that they fall within the segment's data_size boundary. An attacker with CAP_SYS_ADMIN capability can supply a malicious cache device with an out-of-bounds seg_off value, causing the kernel to read past the segment data. The fix adds a bounds check: if (latest.seg_off >= pos->cache_seg->segment.data_size) return -EIO. This requires administrative access and device configuration, limiting the attack surface to privileged users or containers with CAP_SYS_ADMIN.
Affected products
- Linux Linux kernel 5.0 through 7.2 (affected by original dm-pcache introduction; patch applied to stable branches 5.4.y, 5.10.y, 5.15.y, 6.1.y, 6.6.y, 6.9.y, 6.10.y and later)
Timeline
- 2026-09-11: disclosed: CVE-2026-80959 published
- 2026-07-17: patched: Fix committed upstream (commit d1898576090a10d2ac2715218a652e78fb65a6b0)