# CVE-2026-80963

## Summary

- **CVE ID:** CVE-2026-80963
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 16, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

dm-stats: fix a crash if allocation of per-cpu data fails

If "dm_kvzalloc(percpu_alloc_size, cpu_to_node(cpu))" fails, the code
jumps to the "out" label and calls dm_stat_free. dm_stat_free does
"for_each_possible_cpu(cpu) { dm_kvfree(s->stat_percpu[cpu][0].histogram,
s->histogram_alloc_size);", which crashes with NULL pointer dereference
if s->stat_percpu[cpu] is NULL.

This commit fixes the bug by testing s->stat_percpu[cpu] for NULL before
using it.

## Affected Products

- Linux — Linux (fd2ed4d252701d3bbed4cd3e3d267ad469bb832a)
- Linux — Linux (3.12)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (5.10.270)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/c3f211b7a277dd404b4e7d23095be964b5b46a27)
- [CNA](https://git.kernel.org/stable/c/74210fa072960a18bb0eead487585452af722e4f)
- [CNA](https://git.kernel.org/stable/c/0c8f7870ed3ebd512f090d7714cc2c556b9e5c75)
- [CNA](https://git.kernel.org/stable/c/cc87e26d9cce22061dc21e51e11afef29dbbc36a)
- [CNA](https://git.kernel.org/stable/c/e45f0b0c41139810ff395ba2f3cfca1460a5b8a6)
- [CNA](https://git.kernel.org/stable/c/9805d87d0e26c68ee69da3928e665214d2e2851a)
- [CNA](https://git.kernel.org/stable/c/564d17573ef643c13cf6e9015124a205fa65e704)
- [CNA](https://git.kernel.org/stable/c/389a50d094e13724f5f45e6d9d6ef734c98ba291)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.18%
- **EPSS Percentile:** 7.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._