Linux vulnerability

In the Linux kernel, the following vulnerability has been resolved: dm-pcache: clamp the tail kset read to the segment data region The tail-kset read in cache_replay(), the writeback worker and the GC worker bounds its length by PCACHE_SEG_SIZE - seg_off, the raw segment size rather than the data region. A tail near the segment end reads past the segment data into the following control area. Clamp the read to cache_seg_remain(), the data region.

Published 11 Sep 2026Updated 13 Sep 20263 sources
CVSS 7.1

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.