Impact
A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This vulnerability results in a Denial of Service (DoS) for affected systems.
Affected Systems
Affected vendors include Red Hat Enterprise Linux 10, 6, 7, 8, and 9, Red Hat Hardened Images, and Red Hat OpenShift Container Platform 4. The vulnerable component is the libdm library used by the LVM2 package on these distributions.
Risk and Exploitability
The CVSS base score of 5.5 indicates moderate severity; the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Attackers can potentially craft the malicious metadata remotely if they can inject or modify LVM metadata files, or locally if they have write access to such files. The resulting crash only affects availability and does not allow code execution or data exposure. Because the exploitation requires the ability to supply the crafted metadata, the attack vector is inferred rather than explicitly stated in the description.
OpenCVE Enrichment