Impact
The Linux kernel’s dm‑pcache module contains a flaw where cache_replay() follows a chain of on‑media segments without yielding the scheduler. An attacker can create a forged chain that loops back to a segment that has already been visited, causing cache_replay() to iterate indefinitely. This results in an infinite loop that consumes CPU cycles and can make the kernel unresponsive, constituting a denial‑of‑service condition. The weakness is an infinite‑loop flaw (CWE‑835). The description does not indicate any escalation of privileges or remote code execution capability.
Affected Systems
All implementations of the Linux kernel that include the unpatched dm‑pcache code may be affected. The CNA lists Linux:Linux as the affected vendor/product. Precise kernel versions are not specified in the CVE data, so any release containing the vulnerable dm‑pcache path should be considered potentially impacted until the patch is applied.
Risk and Exploitability
The CVSS score is 4.4, indicating moderate severity. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, implying low likelihood of active exploitation. Attackers would need local access to the on‑media segment data to forge a damaging chain; remote exploitation is not supported by the available information.
OpenCVE Enrichment