Out-of-bounds write in Linux kernel - CVE-2026-80962
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local privileged user to perform out-of-bounds reads and writes.
The vulnerability exists due to out-of-bounds access in the dm-pcache cache metadata handling functions cache_segs_init() and get_seg_id() when loading a cache device with crafted on-disk cache metadata. A local privileged user can supply cache metadata containing an oversized segment count or an out-of-range segment identifier to perform out-of-bounds reads and writes.