{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80958","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.809Z","datePublished":"2026-09-11T19:42:25.861Z","dateUpdated":"2026-09-13T06:28:30.422Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:28:30.422Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm-pcache: clamp the tail kset read to the segment data region\n\nThe tail-kset read in cache_replay(), the writeback worker and the GC\nworker bounds its length by PCACHE_SEG_SIZE - seg_off, the raw segment\nsize rather than the data region. A tail near the segment end reads past\nthe segment data into the following control area.\n\nClamp the read to cache_seg_remain(), the data region."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The over-read is reached only through local device-mapper ioctls on /dev/mapper/control (ctl_ioctl requires CAP_SYS_ADMIN, then table_load → dm_pcache_ctr → pcache_cache_start → cache_replay), and later via the writeback and GC workers on that mapped device; no network, Bluetooth, or physical-bus input reaches the kset copy.\nAC:L - An attacker who supplies a crafted DAX/pmem cache image fully controls the persisted key_tail and dirty_tail, so placing a tail near the segment end deterministically copies past data_size; no race, heap layout, or other victim state outside attacker control is required.\nPR:L - dm-ioctl.c gates table load with capable(CAP_SYS_ADMIN), which user-namespace and privileged-container administrators satisfy without init-namespace root; the attacker can attach a DAX cache device they control and load the pcache table themselves.\nUI:N - Exploitation requires only the attacker's own dmsetup/DM_TABLE_LOAD of a crafted pcache cache device; no separate victim must mount media, open files, or take any other action.\nS:U - The out-of-bounds kset read and any resulting kernel oops remain inside the host kernel device-mapper/pcache subsystem; this is not a VM escape, IOMMU bypass, or other cross-authority breakout.\nC:H - copy_mc_to_kernel() copies up to PCACHE_KSET_ONMEDIA_SIZE_MAX (~5 KiB) past segment data_size into the next segment's control area, and on the last segment that continues beyond the DAX mapping into adjacent kernel memory; out-of-bounds reads are High unless limited to a few bytes.\nI:N - The destination is a correctly sized kset buffer (kzalloc or the writeback/GC scratch arrays); this is a source over-read, not an out-of-bounds write, use-after-free, or other kernel-memory corruption or control-flow hijack primitive.\nA:H - Reading past the last DAX-mapped page hits a vmap guard or unmapped hole and oopses the kernel, and a CRC-valid kset assembled across the data/control boundary that is larger than cache_seg_remain() hits BUG_ON in cache_pos_advance(), crashing the host."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/md/dm-pcache/cache_gc.c","drivers/md/dm-pcache/cache_key.c","drivers/md/dm-pcache/cache_writeback.c"],"versions":[{"version":"1d57628ff95b32d5cfa8d8f50e07690c161e9cf0","lessThan":"2cd9776fe3f2d88ec22c36d3c8ba09fbf9d5500c","status":"affected","versionType":"git"},{"version":"1d57628ff95b32d5cfa8d8f50e07690c161e9cf0","lessThan":"1ab55354368d071ebaee4d8c82313955eab65a04","status":"affected","versionType":"git"},{"version":"1d57628ff95b32d5cfa8d8f50e07690c161e9cf0","lessThan":"becf07e2b0053027495ecd671b1f82fb2e615f68","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/md/dm-pcache/cache_gc.c","drivers/md/dm-pcache/cache_key.c","drivers/md/dm-pcache/cache_writeback.c"],"versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/2cd9776fe3f2d88ec22c36d3c8ba09fbf9d5500c"},{"url":"https://git.kernel.org/stable/c/1ab55354368d071ebaee4d8c82313955eab65a04"},{"url":"https://git.kernel.org/stable/c/becf07e2b0053027495ecd671b1f82fb2e615f68"}],"title":"dm-pcache: clamp the tail kset read to the segment data region","x_generator":{"engine":"bippy-1.2.0"}}}}