---
id: CVE-2026-80958
title: >-
  kernel: dm-pcache: clamp the tail kset read to the segment data region
  (CVE-2026-80958)
summary: >-
  A flaw was found in the dm-pcache component of the Linux kernel. The tail-kset
  read operations, used by cache_replay(), the writeback worker, and the garbage
  collection (GC) worker, incorrectly calculate the length of the data region.
  This…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-125
vendor: Red Hat
product: Red Hat OpenShift Container Platform 4
affected:
  - openshift_container_platform 4
published: '2026-09-11'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T17:36:21+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80958.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80958.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-80958'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532108'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-80958'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80958'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-80958.mbox
  - url: 'https://git.kernel.org/stable/c/1ab55354368d071ebaee4d8c82313955eab65a04'
  - url: 'https://git.kernel.org/stable/c/2cd9776fe3f2d88ec22c36d3c8ba09fbf9d5500c'
  - url: 'https://git.kernel.org/stable/c/becf07e2b0053027495ecd671b1f82fb2e615f68'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
  - score-dispute
epss: 0.00124
epssPercentile: 0.02437
scores:
  vendor: 5.1
  cna: 7.1
ingestedAt: '2026-09-14T15:23:07.476Z'
---

## Overview

A flaw was found in the dm-pcache component of the Linux kernel. The tail-kset read operations, used by cache_replay(), the writeback worker, and the garbage collection (GC) worker, incorrectly calculate the length of the data region. This error causes the system to read beyond the intended segment data into an adjacent control area, which could lead to information disclosure or system instability.

## Vendor advisories

- **Red Hat VEX** · Moderate · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80958.json)

**kernel: dm-pcache: clamp the tail kset read to the segment data region** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.

Not affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

## Remediation

Refer to the advisory for fix availability.
