Impact
The dm‑verity module in the Linux kernel contains a flaw that can cause a NULL pointer dereference when loading a block device that lacks a device‑mapper table. This dereference would trigger a kernel OOPS and lead to a system crash, thereby denying service.
Affected Systems
The dm‑verity subsystem is part of the Linux kernel. All distributions shipping a kernel that includes dm‑verity with the fault unpatched are affected. No specific kernel release numbers appear in the data, so any kernel version prior to the commit introducing the fix is considered vulnerable. The vendor/product information indicates the entire Linux kernel is impacted.
Risk and Exploitability
The vulnerability requires the creation or loading of a block device without a device‑mapper table. Based on the description, it is inferred that an attacker would need local or privileged access to perform such operations, as no remote trigger is mentioned. The resulting kernel panic does not allow arbitrary code execution but does cause a denial of service. The CVSS score of 5.5 reflects medium severity; the EPSS score is less than 1%, and the vulnerability is not listed in CISA KEV, suggesting a low probability of real‑world exploitation.
OpenCVE Enrichment