Impact
This vulnerability is a use‑after‑free and invalid segment operation in the dm‑pcache key replay path of the Linux kernel. When a key’s generation is stale, a freed memory block is accessed, creating a use‑after‑free condition that can corrupt kernel memory. The flaw, identified as CWE‑825, could lead to a system crash or unintended kernel data manipulation. No explicit capability for privilege escalation or arbitrary code execution is documented in the given description.
Affected Systems
All Linux kernel builds that include the dm‑pcache subsystem and have not yet applied the recent patch are affected. The issue exists in kernel releases that use the pre‑patch implementation of kset_replay().
Risk and Exploitability
The CVSS score of 7.8 indicates moderate‑to‑high impact. EPSS is < 1% and the vulnerability is not listed in CISA KEV. The likely attack vector requires local or privileged access to trigger the cache replay logic, limiting immediate exploitation risk. Successful exploitation would cause kernel memory corruption, potentially leading to system instability.
OpenCVE Enrichment