{"id":"CVE-2026-80958","title":"kernel: dm-pcache: clamp the tail kset read to the segment data region (CVE-2026-80958)","summary":"A flaw was found in the dm-pcache component of the Linux kernel. The tail-kset read operations, used by cache_replay(), the writeback worker, and the garbage collection (GC) worker, incorrectly calculate the length of the data region. This…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-125","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","affected":["openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T17:36:21+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80958.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80958.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-80958"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532108"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80958"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80958"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-80958.mbox"},{"url":"https://git.kernel.org/stable/c/1ab55354368d071ebaee4d8c82313955eab65a04"},{"url":"https://git.kernel.org/stable/c/2cd9776fe3f2d88ec22c36d3c8ba09fbf9d5500c"},{"url":"https://git.kernel.org/stable/c/becf07e2b0053027495ecd671b1f82fb2e615f68"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00124,"epssPercentile":0.02438,"scores":{"vendor":5.1,"cna":7.1},"ingestedAt":"2026-09-14T15:23:07.476Z","slug":"CVE-2026-80958","body":"## Overview\n\nA flaw was found in the dm-pcache component of the Linux kernel. The tail-kset read operations, used by cache_replay(), the writeback worker, and the garbage collection (GC) worker, incorrectly calculate the length of the data region. This error causes the system to read beyond the intended segment data into an adjacent control area, which could lead to information disclosure or system instability.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80958.json)\n\n**kernel: dm-pcache: clamp the tail kset read to the segment data region** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":204235,"id":"CVE-2026-80958","ts":1789490240447,"field":"cvss","old":"5.1","new":"5.5"},{"seq":202937,"id":"CVE-2026-80958","ts":1789403733024,"field":"cvss","old":"7.1","new":"5.1"},{"seq":202936,"id":"CVE-2026-80958","ts":1789403733024,"field":"severity","old":"high","new":"medium"},{"seq":183612,"id":"CVE-2026-80958","ts":1789356676101,"field":"cvss","old":"7.1","new":"5.1"},{"seq":183611,"id":"CVE-2026-80958","ts":1789356676101,"field":"severity","old":"high","new":"medium"},{"seq":153142,"id":"CVE-2026-80958","ts":1789285349215,"field":"cvss","old":null,"new":"7.1"},{"seq":153141,"id":"CVE-2026-80958","ts":1789285349215,"field":"severity","old":"none","new":"high"},{"seq":109582,"id":"CVE-2026-80958","ts":1789183732503,"field":"cvss","old":null,"new":"5.1"},{"seq":109581,"id":"CVE-2026-80958","ts":1789183732503,"field":"severity","old":"none","new":"medium"}]}