Answer in brief
CVE-2026-80963 records a Unknown severity vulnerability in dm-stats: fix a crash if allocation of per-cpu data fails. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=fd2ed4d252701d3bbed4cd3e3d267ad469bb832a <c3f211b7a277dd404b4e7d23095be964b5b46a27 || >=fd2ed4d252701d3bbed4cd3e3d267ad469bb832a <74210fa072960a18bb0eead487585452af722e4f || >=fd2ed4d252701d3bbed4cd3e3d267ad469bb832a <0c8f7870ed3ebd512f090d7714cc2c556b9e5c75 || >=fd2ed4d252701d3bbed4cd3e3d267ad469bb832a <cc87e26d9cce22061dc21e51e11afef29dbbc36a | c3f211b7a277dd404b4e7d23095be964b5b46a27, 74210fa072960a18bb0eead487585452af722e4f, 0c8f7870ed3ebd512f090d7714cc2c556b9e5c75, cc87e26d9cce22061dc21e51e11afef29dbbc36a |
| Linux/Linuxgeneric | 3.12 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: dm-stats: fix a crash if allocation of per-cpu data fails If "dm_kvzalloc(percpu_alloc_size, cpu_to_node(cpu))" fails, the code jumps to the "out" label and calls dm_stat_free. dm_stat_free does "for_each_possible_cpu(cpu) { dm_kvfree(s->stat_percpu[cpu][0].histogram, s->histogram_alloc_size);", which crashes with NULL pointer dereference if s->stat_percpu[cpu] is NULL. This commit fixes the bug by testing s->stat_percpu[cpu] for NULL before using it.
Quoted source text, attributed separately from HOL analysis.