PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-80960 Linux CVE debrief

The Linux kernel's dm-pcache module is vulnerable to an out-of-bounds write due to improper validation of on-media seg_num against the cache device size. This issue can be triggered at table load by a user with CAP_SYS_ADMIN privileges, potentially leading to a denial of service or privilege escalation. Administrators should assess their exposure and apply patches or mitigations as necessary. The vulnerability is resolved in the Linux kernel through a fix that validates seg_num against the cache device size, preventing out-of-bounds writes.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-11
Original CVE updated
2026-09-11
Advisory published
2026-09-11
Advisory updated
2026-09-11

Who should care

Linux kernel administrators and users with CAP_SYS_ADMIN privileges should assess their exposure and apply patches or mitigations as necessary to prevent potential denial of service or privilege escalation. Security teams and vulnerability management teams should prioritize patching and monitor for unusual activity related to the dm-pcache module. System administrators responsible for Linux kernel deployments should review and apply patches or mitigations.

Why it matters

Linux kernel administrators and users with CAP_SYS_ADMIN privileges should assess their exposure and apply patches or mitigations as necessary to prevent potential denial of service or privilege escalation.

  • Potential denial of service due to out-of-bounds write
  • Possible privilege escalation for users with CAP_SYS_ADMIN privileges
  • Need for patch application or mitigation to prevent exploitation

Technical summary

The Linux kernel's dm-pcache module is vulnerable to an out-of-bounds write due to improper validation of on-media seg_num against the cache device size. This can be exploited by a user with CAP_SYS_ADMIN privileges at table load, potentially leading to a denial of service or privilege escalation. The vulnerability is resolved through a fix that validates seg_num against the cache device size, preventing out-of-bounds writes. Technical details indicate that seg_num is read from the crc32c-only superblock and controls the size of cache->segments[].

Defensive priority

High

Recommended defensive actions

  • Review and apply the provided patches to the Linux kernel's dm-pcache module
  • Restrict CAP_SYS_ADMIN privileges to trusted users
  • Monitor systems for unusual activity related to the dm-pcache module
  • Perform a thorough review of system logs to detect potential exploitation attempts
  • Inventory affected systems and prioritize patching based on risk assessment
  • Implement compensating controls for exposed systems while remediation is scheduled
  • Track exceptions and retest remediated assets to ensure vulnerability closure

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in the Linux kernel's dm-pcache module. The vulnerability allows for an out-of-bounds write due to improper validation of on-media seg_num against the cache device size. Evidence is based on the official CVE Program record and NIST NVD detail page. Defensive verification tasks include reviewing system logs for unusual activity related to the dm-pcache module and ensuring that patches or mitigations are applied.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-80960 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-80960

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-80960 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80960

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/62d92e45abe9e087370f9fc5d876b95673aced34

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/91b93fe5cf4d62d5ecc642a6c8f15a3c11b00e3c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e889c0ee81165fc90aad2979b51f930f77895703

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.