Impact
The Linux kernel dm‑pcache driver contains a logic flaw that allows the allocator to return cache segment structures that have not been fully initialized. When a crafted dm‑cache image advertises fewer segments than the device actually holds, the remaining segment structs are left zeroed, with a NULL data pointer. Closing such a segment causes the driver to write through this NULL pointer, leading to a null‑pointer dereference that corrupts kernel memory. While this flaw does not guarantee arbitrary code execution, the memory corruption could disrupt kernel operation or be leveraged to elevate privileges if an attacker can supply a malicious dm‑cache image. The likely attack vector is the introduction of a malformed dm‑cache image; this inference is based on the description since the attack method is not explicitly stated.
Affected Systems
This flaw exists in the dm‑pcache component of the Linux kernel. Any kernel version released before is affected. No specific version list is supplied, so all unpatched kernel releases that enable dm‑pcache are potentially at risk.
Risk and Exploitability
The vulnerability is scored 4.4 on the CVSS scale, indicating low severity. Its EPSS score is less than 1%, showing a very low exploitation probability. It is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a malformed dm‑cache image and the target must have dm‑pcache enabled. Because the malicious image must be loaded by the kernel, the attack is limited to environments where such images can be introduced, such as container images or disk snapshots. The lack of a null check and the resultant kernel memory corruption make the bug dangerous when dm‑pcache is in use, but the overall threat remains modest due to the low EPSS and the need for privileged image creation. The attack vector is inferred from the requirement to supply a malicious dm‑cache image, as the description does not explicitly state the vector.
OpenCVE Enrichment