CVE-2026-80956
In the Linux kernel, the following vulnerability has been resolved: dm-pcache: only hand out initialized cache segments get_cache_segment() scans the segment map up to cache->n_segs, the physical device segment count, but cache_segs_init() only initializes the first cache_info->n_segs segments. A crafted image with cache_info->n_segs smaller than the device count leaves the remaining pcache_cache_segment structs zeroed (segment.data == NULL), and the allocator can hand one to cache_kset_close(), which writes through the returned segment's data pointer with no NULL check. Bound the allocator's search to cache_info->n_segs so only initialized segments are ever returned. A conforming cache sets n_segs equal to the device segment count, so this rejects nothing legitimate.
Affected versions
Linux kernel versions
6.18
and later are affected. Fixed in
6.18.50,
7.2.4,
7.3-rc1
and their respective stable series.
References
3 totalFrequently asked questions
-
What is CVE-2026-80956?
CVE-2026-80956 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.18 onward and has been patched in 6.18.50, 7.2.4 and 7.3-rc1. CVE-2026-80956 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-80956?
Yes. CVE-2026-80956 has been patched. Fixed versions include 6.18.50, 7.2.4 and 7.3-rc1. If you are running Linux kernel 6.18 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-80956 actively exploited?
No. CVE-2026-80956 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.