CVE-2026-80963

Summary

In the Linux kernel, the following vulnerability has been resolved:

dm-stats: fix a crash if allocation of per-cpu data fails

If "dm_kvzalloc(percpu_alloc_size, cpu_to_node(cpu))" fails, the code jumps to the "out" label and calls dm_stat_free. dm_stat_free does "for_each_possible_cpu(cpu) { dm_kvfree(s->stat_percpu[cpu][0].histogram, s->histogram_alloc_size);", which crashes with NULL pointer dereference if s->stat_percpu[cpu] is NULL.

This commit fixes the bug by testing s->stat_percpu[cpu] for NULL before using it.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxfd2ed4d252701d3bbed4cd3e3d267ad469bb832a < c3f211b7a277dd404b4e7d23095be964b5b46a27affected
LinuxLinuxfd2ed4d252701d3bbed4cd3e3d267ad469bb832a < 74210fa072960a18bb0eead487585452af722e4faffected
LinuxLinuxfd2ed4d252701d3bbed4cd3e3d267ad469bb832a < 0c8f7870ed3ebd512f090d7714cc2c556b9e5c75affected
LinuxLinuxfd2ed4d252701d3bbed4cd3e3d267ad469bb832a < cc87e26d9cce22061dc21e51e11afef29dbbc36aaffected
LinuxLinux3.12affected
LinuxLinux0 < 3.12unaffected
LinuxLinux6.12.109 <= 6.12.*unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References