Out-of-bounds read in Linux kernel - CVE-2026-80959
Published: September 13, 2026
Vulnerability details
The vulnerability allows a local privileged user to read past the segment data.
The vulnerability exists due to an out-of-bounds read in cache_pos_decode() in dm-pcache when decoding persisted key_tail and dirty_tail segment offsets from a supplied cache device. A local privileged user can supply a cache device containing a segment offset at or beyond the segment data size to read past the segment data.