CVE-2026-80963: dm-stats: fix a crash if allocation of per-cpu data fails
Published Sep 11, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
dm-stats: fix a crash if allocation of per-cpu data fails
If "dmkvzalloc(percpuallocsize, cputonode(cpu))" fails, the code jumps to the "out" label and calls dmstatfree. dmstatfree does "foreachpossiblecpu(cpu) { dmkvfree(s->statpercpu[cpu][0].histogram, s->histogramallocsize);", which crashes with NULL pointer dereference if s->statpercpu[cpu] is NULL.
This commit fixes the bug by testing s->statpercpu[cpu] for NULL before using it.
Affected Software
1 affected component
Linux Kernel
Event History
Sep 11, 2026
CVE Published
via MITRE·07:42 PM
Data Sourced
via MITRE·07:42 PM
Description
Frequently Asked Questions
1
What condition is required for the crash to occur?
A per-CPU allocation performed by dm-stats must fail. During cleanup of that failed allocation, the affected code dereferences a NULL per-CPU statistics pointer.