Impact
The flaw occurs in the dm-pcache component of the Linux kernel where tail‑kset reads in cache_replay(), the writeback worker, and the GC worker were bounded by the raw segment size instead of the data region. A tail read near the end of a segment can therefore access memory beyond the data area and into the subsequent control area. This off‑by‑one read permits an attacker to read arbitrary kernel memory contents located past the segment data, thereby leaking sensitive information such as process data, credentials, or cryptographic keys. The weakness is a classic buffer overread (CWE-125).
Affected Systems
All Linux kernel builds that enable the dm-pcache device are vulnerable until the kernel patch that clamps the tail read to the data region is applied. No specific kernel version is listed in the advisory, so every unpatched kernel containing the affected code path is regarded as affected. It is inferred that dm-pcache exists in many Linux distributions.
Risk and Exploitability
The advisory reports a CVSS score of 7.1, indicating a high severity scenario. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or partially local through a user who can interact with a dm-pcache device, as the flaw does not provide remote code execution or privilege escalation. Nevertheless, the ability to read arbitrary kernel memory could lead to sensitive data exposure, and the risk remains non‑negligible because kernel memory is typically protected and not normally exposed to users.
OpenCVE Enrichment