CVE-2026-72104: dm-pcache: reject option groups without values
In the Linux kernel, the following vulnerability has been resolved:
dm-pcache: reject option groups without values
The pcache target parses optional arguments as name/value pairs. A table that advertises one optional argument and supplies only a recognized option name, for example "cachemode", reaches parsecacheopts() with argc == 1. The parser consumes the name, decrements argc to zero, then calls dmshiftarg() again for the value. dmshiftarg() returns NULL when no arguments remain, and the following strcmp() dereferences that NULL pointer.
Check that each recognized option has a value before consuming it. This keeps valid "cachemode writeback" and "datacrc true/false" tables unchanged while making malformed tables fail during target construction with a precise missing-value error.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72104?
CVE-2026-72104 has been assigned a risk score of 27.
How do I fix CVE-2026-72104?
To resolve CVE-2026-72104, ensure that all option groups in the pcache target include valid name/value pairs.
What systems are affected by CVE-2026-72104?
CVE-2026-72104 affects the Linux kernel in systems using dm-pcache with improperly defined option groups.
What does CVE-2026-72104 impact in the Linux kernel?
CVE-2026-72104 impacts the dm-pcache component by allowing option groups without values to be rejected.
When was CVE-2026-72104 published?
CVE-2026-72104 was published on August 15, 2026.