CVE-2026-80958Medium· 5.5▾ SunlitA flaw was found in the dm-pcache component of the Linux kernel. The tail-kset read operations, used by cache_replay(), the writeback worker, and the garbage collection (GC) worker, incorrectly calculate the length of the data region. This…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 5.1
none → medium
— → 7.1
none → high
Last analysed / modified upstream
7.1 → 5.1
high → medium
7.1 → 5.1
high → medium
5.1 → 5.5
A flaw was found in the dm-pcache component of the Linux kernel. The tail-kset read operations, used by cache_replay(), the writeback worker, and the garbage collection (GC) worker, incorrectly calculate the length of the data region. This error causes the system to read beyond the intended segment data into an adjacent control area, which could lead to information disclosure or system instability.
kernel: dm-pcache: clamp the tail kset read to the segment data region — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.
Not affected:
Refer to the advisory for fix availability.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-80959Medium· 5.5kernel: dm-pcache: bound the persisted tail-position offset (CVE-2026-80959)
CVE-2026-89571Medium· 5.5kernel: cxl/features: bound fwctl command payload to the input buffer (CVE-2026-89571)
CVE-2026-89614Medium· 5.5kernel: ntfs: bound the free-cluster bitmap scan to the volume (CVE-2026-89614)
CVE-2026-80962Medium· 5.5kernel: dm-pcache: validate geometry fields from on-disk cache_info (CVE-2026-80962)
CVE-2026-89743Medium· 5.5kernel: misc: nsm: bound the device-reported response length (CVE-2026-89743)
CVE-2026-89621Medium· 5.5kernel: HID: mcp2221: validate report size in mcp2221_raw_event() (CVE-2026-89621)