SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-80963

UNKNOWN · CVSS N/A EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's dm-stats component, where a failure in allocating per-CPU data can lead to a NULL pointer dereference, causing a crash. This issue can disrupt system stability and should be prioritized by organizations running Linux environments, particularly those utilizing device-mapper statistics. Immediate attention is recommended to mitigate potential downtime and maintain system reliability.

CVE
CVE-2026-80963
Severity
UNKNOWN
CVSS
N/A
EPSS
0.18%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: dm-stats: fix a crash if allocation of per-cpu data fails If "dm_kvzalloc(percpu_alloc_size, cpu_to_node(cpu))" fails, the code jumps to the "out" label and calls dm_stat_free. dm_stat_free does "for_each_possible_cpu(cpu) { dm_kvfree(s->stat_percpu[cpu][0].histogram, s->histogram_alloc_size);", which crashes with NULL pointer dereference if s->stat_percpu[cpu] is NULL. This commit fixes the bug by testing s->stat_percpu[cpu] for NULL before using it.