Junglewise Threat Intelligence

CVE-2026-80962: Linux kernel dm-pcache out-of-bounds access via invalid geometry

CVE-2026-80962 · Severity: high · CVSS 7.8 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's device-mapper persistent cache (dm-pcache) module fails to validate untrusted metadata from cache devices, allowing a privileged user to supply malicious cache geometry that triggers out-of-bounds memory reads and writes. This can lead to kernel crashes, information disclosure, or potential privilege escalation on systems using dm-pcache for caching.

Technical details

The vulnerability is an out-of-bounds access flaw in dm-pcache's cache initialization code. The `cache_segs_init()` function iterates based on `n_segs` from untrusted on-disk metadata (CRC-protected only with a fixed public seed) to index the `cache->segments[]` array, and `get_seg_id()` reads segment IDs without bounds checking. A privileged attacker (CAP_SYS_ADMIN) can supply a malicious cache device with an oversized `n_segs` value or out-of-range segment IDs to cause out-of-bounds array access and wild pointer dereferences, leading to reads and writes from arbitrary kernel memory. The fix validates that `n_segs` does not exceed the device segment count and that segment IDs fall within valid range before use, rejecting invalid metadata at load time.

Affected products

  • Linux Linux kernel multiple versions from 2.6.11 through 6.x (see git commits)

Timeline

  • 2026-09-11: disclosed: CVE-2026-80962 published
  • 2026-07-17: patched: Commit 32d1809da31094ef76fd98dc1f1a8b55ca1295dd merged upstream
  • 2026-09-07: patched: Backported to stable via commit 3e19172089ec81132a8a48e802b1034a744209f4

References

Related threats