Out-of-bounds read in Linux kernel - CVE-2026-80961
Published: September 13, 2026
Vulnerability details
The vulnerability allows a local privileged user to read out-of-bounds memory.
The vulnerability exists due to an out-of-bounds read in dm-pcache kset metadata handling when processing kset headers from a supplied cache device. A local privileged user can supply cache-device metadata with an oversized key_num value to read beyond the kset buffer bounds.
The kset CRC uses a fixed public seed.