« Volver al listado

CVE-2026-80956

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

dm-pcache: only hand out initialized cache segments

get_cache_segment() scans the segment map up to cache->n_segs, the physical device segment count, but cache_segs_init() only initializes the first cache_info->n_segs segments. A crafted image with cache_info->n_segs smaller than the device count leaves the remaining pcache_cache_segment structs zeroed (segment.data == NULL), and the allocator can hand one to cache_kset_close(), which writes through the returned segment's data pointer with no NULL check.

Bound the allocator's search to cache_info->n_segs so only initialized segments are ever returned. A conforming cache sets n_segs equal to the device segment count, so this rejects nothing legitimate.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80956",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "1d57628ff95b32d5cfa8d8f50e07690c161e9cf0",
              "lessThan": "83e3116283ed2c6a6a1fa662862a4b4d7d2701a2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1d57628ff95b32d5cfa8d8f50e07690c161e9cf0",
              "lessThan": "692037ae1a7cfacc2f0c22c6e034c1dfee0e553f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1d57628ff95b32d5cfa8d8f50e07690c161e9cf0",
              "lessThan": "2df0fc042e299bae3c0f60ea5cd2af9285658e9f",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/md/dm-pcache/cache_segment.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.18"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.18",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/md/dm-pcache/cache_segment.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:01.410",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2df0fc042e299bae3c0f60ea5cd2af9285658e9f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/692037ae1a7cfacc2f0c22c6e034c1dfee0e553f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/83e3116283ed2c6a6a1fa662862a4b4d7d2701a2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-pcache: only hand out initialized cache segments\n\nget_cache_segment() scans the segment map up to cache->n_segs, the\nphysical device segment count, but cache_segs_init() only initializes\nthe first cache_info->n_segs segments. A crafted image with\ncache_info->n_segs smaller than the device count leaves the remaining\npcache_cache_segment structs zeroed (segment.data == NULL), and the\nallocator can hand one to cache_kset_close(), which writes through the\nreturned segment's data pointer with no NULL check.\n\nBound the allocator's search to cache_info->n_segs so only initialized\nsegments are ever returned. A conforming cache sets n_segs equal to the\ndevice segment count, so this rejects nothing legitimate."
    }
  ],
  "lastModified": "2026-09-11T20:19:01.410",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}