Impact
In the Linux kernel, the device‑mapper cache (dm‑pcache) component decodes offsets representing the persisted tail position. The function cache_pos_decode() takes the persisted key_tail and dirty_tail seg_off from the cache device and uses them to calculate addresses within the segment. When a seg_off at or past the segment data_size, controllable by anyone who supplies the device (CAP_SYS_ADMIN), is decoded, the driver reads past the end of the segment data. This out-of-bounds read can expose portions of kernel memory to a privileged user. The weakness corresponds to CWE‑125.
Affected Systems
All Linux systems that include the dm‑pcache driver in the kernel are affected. The vulnerability exists in any kernel build that loads dm‑pcache without the recent bounds‑check patch. Users with capabilities to supply CAP_SYS_ADMIN or equivalent root privileges are the ones who can trigger the fault.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity local‑privileged information‑leak scenario requiring a crafted device for the dm‑pcache driver. The EPSS score of < 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Consequently, the threat is primarily a local‑privileged information‑leak scenario for systems that expose dm‑pcache devices to privileged users.
OpenCVE Enrichment