From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6933B566C79 for ; Fri, 11 Sep 2026 19:47:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156043; cv=none; b=BK64bMLfgCj3YarOf+wCEon0Hrwf1d00gohnu8QE/OgVkL7QafQEcHu9w1mwmavBM2JqDTAtSGQGJpJlpR6NLkAjI3NSpuezTpFXx3XDAfVkJpXIAVZRBzobz1CDQGFt8PIXyY00UTttDz0dNX8PAZdUn3kKoVf7UqWjZ+CHXeU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156043; c=relaxed/simple; bh=Urs9oyd1znpQrUDkaNV9SOnIPd+GY7N1hypp6jrkWHI=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=JoGxq2HfTO4mly37jXV+gyfldI1ffQe3fRjPKRm9/l1yUYBi0xEqzGPSYGLBI56PXB7kZ8YukByBsM+UEZX5agL/MMRvZQpqB2XB1pBVgDlOVz/ujs2TMlWLK7Xz8BUefCTgylLaUqmeOGRUexeuztFTPMEIFULLCiY/am+odLY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=h+uiq6U4; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="h+uiq6U4" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 211171F000FF; Fri, 11 Sep 2026 19:47:04 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156025; bh=eGXR53b80Ih0DxpJSWAbOCVBii+9Zy7aFq2adZ8T1Yo=; h=From:To:Cc:Subject:Date:Reply-To; b=h+uiq6U4oWY75jYPqxndB6Cl+lyc7+DKpmH0uQZ+Xw4KO5b4J2+pwQcn560TJoJuE wrxmHLSTbe6nWxR2WU5AfCigjm+fp1/XIct7Ce1H+HDjPdiOLjy9Feo1Han4W80kRa I2w13uw8z3jGgq1g1KaiUIqx/E4iAA6/4S32sDDI= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80955: dm-pcache: fix use-after-free and invalid seg operations in kset_replay() Date: Fri, 11 Sep 2026 21:41:01 +0200 Message-ID: <2026091140-CVE-2026-80955-7474@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2740; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=UkknkBeBoQALELyCDWnE0FtRnFMECJcD7SwK37F83zg=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIi32+XjdfxW5pX32s3s2EyItk4sbSpfMY/+6VGHPj 0WXF5Zd6IhlYRBkYpAVU2T5so3n6P6KQ4pehranYeawMoEMYeDiFICJsPgwzHfbvUBmQ9UhdoH7 EoY+L0+vUT3pdJthvkepWMhaTkvNaU9WvUr9/6O+dHL8NgA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: dm-pcache: fix use-after-free and invalid seg operations in kset_replay() In kset_replay, when key->seg_gen is stale (key->seg_gen < key->cache_pos.cache_seg->gen), cache_key_put(key) is called but then key->cache_pos.cache_seg is accessed as the argument to cache_seg_get(). This is a use-after-free on the freed key memory. Although mempool recycled memory is not immediately reclaimed or overwritten in practice, this is still a potential UAF bug. Additionally, for expired invalid keys, setting the cache->seg_map bit and calling cache_seg_get() is unreasonable since the corresponding segment data is no longer valid. Fix both issues by moving cache_seg_get() and __set_bit() after the gen check, so they only execute for valid keys, and using continue to skip invalid keys. The Linux kernel CVE team has assigned CVE-2026-80955 to this issue. Affected and fixed versions =========================== Issue introduced in 6.18 with commit 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 and fixed in 6.18.50 with commit 1894fc7a3bab90143dcd26ef8ee27040ef4a7501 Issue introduced in 6.18 with commit 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 and fixed in 7.2.4 with commit f39a3e9cc5946473e16d6f5071b2ee0216c56d06 Issue introduced in 6.18 with commit 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 and fixed in 7.3-rc1 with commit c2e894eac398b258f12fdec73ed6ba081047f7b3 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80955 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/md/dm-pcache/cache_key.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/1894fc7a3bab90143dcd26ef8ee27040ef4a7501 https://git.kernel.org/stable/c/f39a3e9cc5946473e16d6f5071b2ee0216c56d06 https://git.kernel.org/stable/c/c2e894eac398b258f12fdec73ed6ba081047f7b3