Linux vulnerability

In the Linux kernel, the following vulnerability has been resolved: dm-pcache: bound the persisted tail-position offset cache_pos_decode() takes the persisted key_tail and dirty_tail seg_off from the cache device and addresses within the segment with it. A seg_off at or past the segment data_size, controllable by whoever supplies the device (CAP_SYS_ADMIN), reads past the segment data. Reject a decoded seg_off that is not below the segment data_size.

Published 11 Sep 2026Updated 13 Sep 20263 sources
CVSS 7.8

What happened

In the Linux kernel, the following vulnerability has been resolved: dm-pcache: bound the persisted tail-position offset cache_pos_decode() takes the persisted key_tail and dirty_tail seg_off from the cache device and addresses within the segment with it. A seg_off at or past the segment data_size, controllable by whoever supplies the device (CAP_SYS_ADMIN), reads past the segment data. Reject a decoded seg_off that is not below the segment data_size.

Affected versions

Linux: 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 through before ffd9a214a94f9928e54856f42b1cc3e33fb10e36 (git); 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 through before 8bf7a06ca3c1611809725f58cfd573f2ffbda75f (git); 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 through before d1898576090a10d2ac2715218a652e78fb65a6b0 (git); 6.18 Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

No public PoC reference has passed the current publication threshold.