CVE-2026-80961
CVE CVE-2026-80961EUVD EUVD-2026-76284Published 2026-09-11T19:42:27.000ZLast changed 2026-09-13T06:28:32.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate kset key_num and intra-segment bounds Two more fields decoded from the cache device go unbounded. The kset key_num drives cache_kset_crc() and the replay loop in cache_replay(), the writeback worker and the GC worker, but only the magic and a fixed-seed CRC are checked first, so a non-last kset whose key_num exceeds the PCACHE_KSET_KEYS_MAX buffer reads past its end before the CRC compare. A key's intra-segment offset and length in cache_key_decode() are taken verbatim, so a key running past its segment is replayed into the cache tree and the data CRC check and every later read hit then copy adjacent persistent memory into the caller's bio -- an out-of-bounds read that leaks to user space. Both fields are controlled by whoever supplies the cache device (CAP_SYS_ADMIN); the CRC seed is public. Add kset_onmedia_valid() to bound key_num before any kset read, and reject a key whose offset plus length, computed in 64 bits, exceeds the segment data_size. Valid metadata is unaffected.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.18.50; patch: 0; 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 <f11deb032fd84081e7831cffcba895d893054a22; 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 <5ac38f4b4862fad6e7270fde5c3356a822ce74ca; patch: 7.3-rc1; 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 <d8caf96040a06096276ab72f5e1e8547c014c564; patch: 7.2.4; 6.18
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.