Junglewise Threat Intelligence

CVE-2026-80960: Linux kernel dm-pcache heap overflow via invalid seg_num

CVE-2026-80960 · Severity: info · CVSS 7.1 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's dm-pcache persistent cache target contains a validation flaw that allows an attacker with system administrator privileges to trigger an out-of-bounds write into kernel heap memory during cache device initialization. By providing a maliciously crafted cache device with an invalid segment count value, an attacker can cause up to 12 KB of uncontrolled memory writes, potentially leading to privilege escalation or denial of service.

Technical details

The vulnerability exists in the dm-pcache module's cache_dev.c file, where the segment count (seg_num) read from the cache device superblock is not validated against the actual device size before being used to allocate and initialize cache segments. The seg_num value controls array bounds and segment iteration, yet no check ensures it does not exceed the physical device capacity. An attacker with CAP_SYS_ADMIN can supply a crafted device with an invalid seg_num, causing CACHE_DEV_SEGMENT() macro calls to resolve beyond the DAX mapping into kernel memory. The cache_seg_init() function then calls cache_dev_zero_range() which performs a memset() operation up to 12 KB past valid memory. The fix adds explicit validation to reject seg_num values that are zero, exceed device capacity, or exceed PCACHE_CACHE_SEGS_MAX before use.

Affected products

  • Linux Linux kernel multiple versions (dm-pcache component)

Timeline

  • 2026-09-11: disclosed: CVE-2026-80960 published in NVD
  • 2026-07-17: patched: Fix committed upstream (commit 62d92e45abe9e087370f9fc5d876b95673aced34)
  • 2026-09-07: patched: Fix backported to stable trees

References

Related threats