CVE-2026-80963

medium

Description

In the Linux kernel, the following vulnerability has been resolved: dm-stats: fix a crash if allocation of per-cpu data fails If "dm_kvzalloc(percpu_alloc_size, cpu_to_node(cpu))" fails, the code jumps to the "out" label and calls dm_stat_free. dm_stat_free does "for_each_possible_cpu(cpu) { dm_kvfree(s->stat_percpu[cpu][0].histogram, s->histogram_alloc_size);", which crashes with NULL pointer dereference if s->stat_percpu[cpu] is NULL. This commit fixes the bug by testing s->stat_percpu[cpu] for NULL before using it.

References

https://git.kernel.org/stable/c/e45f0b0c41139810ff395ba2f3cfca1460a5b8a6

https://git.kernel.org/stable/c/cc87e26d9cce22061dc21e51e11afef29dbbc36a

https://git.kernel.org/stable/c/c3f211b7a277dd404b4e7d23095be964b5b46a27

https://git.kernel.org/stable/c/9805d87d0e26c68ee69da3928e665214d2e2851a

https://git.kernel.org/stable/c/74210fa072960a18bb0eead487585452af722e4f

https://git.kernel.org/stable/c/564d17573ef643c13cf6e9015124a205fa65e704

https://git.kernel.org/stable/c/389a50d094e13724f5f45e6d9d6ef734c98ba291

https://git.kernel.org/stable/c/0c8f7870ed3ebd512f090d7714cc2c556b9e5c75

Details

Source: Mitre, NVD

Published: 2026-09-11

Updated: 2026-09-14

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00168