Impact
In the Linux kernel, an issue existed in the dm-integrity subsystem where the remaining space of a device’s tuple was not properly zeroed when the hash size was smaller than the tuple size. This caused uninitialized kernel memory to remain readable, enabling potential information disclosure of sensitive kernel data.
Affected Systems
All Linux kernel installations that include the dm-integrity module compiled into the kernel before the patch commit are affected. The issue applies to all vendors, as the module is part of the standard kernel source tree.
Risk and Exploitability
The CVSS score is 5.5 and the EPSS is < 1%, and the vulnerability is not listed in CISA’s KEV catalog. The leak originates from kernel space and can be triggered by interacting with a dm-integrity device. Based on the description, it is inferred that local user privileges are required to access the device, and the likely attack vector is local use of the affected dm-integrity device. The absence of a publicly available exploit does not eliminate risk; the confidentiality impact of kernel memory exposure is high and the required access level suggests a moderate to high likelihood of exploitation by attackers who can gain local access.
OpenCVE Enrichment
Debian DLA