CVE-2026-80963
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
dm-stats: fix a crash if allocation of per-cpu data fails
If "dm_kvzalloc(percpu_alloc_size, cpu_to_node(cpu))" fails, the code jumps to the "out" label and calls dm_stat_free. dm_stat_free does "for_each_possible_cpu(cpu) { dm_kvfree(s->stat_percpu[cpu][0].histogram, s->histogram_alloc_size);", which crashes with NULL pointer dereference if s->stat_percpu[cpu] is NULL.
This commit fixes the bug by testing s->stat_percpu[cpu] for NULL before using it.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | fd2ed4d252701d3bbed4cd3e3d267ad469bb832a < c3f211b7a277dd404b4e7d23095be964b5b46a27 | affected |
| Linux | Linux | fd2ed4d252701d3bbed4cd3e3d267ad469bb832a < 74210fa072960a18bb0eead487585452af722e4f | affected |
| Linux | Linux | fd2ed4d252701d3bbed4cd3e3d267ad469bb832a < 0c8f7870ed3ebd512f090d7714cc2c556b9e5c75 | affected |
| Linux | Linux | fd2ed4d252701d3bbed4cd3e3d267ad469bb832a < cc87e26d9cce22061dc21e51e11afef29dbbc36a | affected |
| Linux | Linux | 3.12 | affected |
| Linux | Linux | 0 < 3.12 | unaffected |
| Linux | Linux | 6.12.109 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.50 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.4 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/c3f211b7a277dd404b4e7d23095be964b5b46a27
- https://git.kernel.org/stable/c/74210fa072960a18bb0eead487585452af722e4f
- https://git.kernel.org/stable/c/0c8f7870ed3ebd512f090d7714cc2c556b9e5c75
- https://git.kernel.org/stable/c/cc87e26d9cce22061dc21e51e11afef29dbbc36a
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.