Impact
During a device‑mapper table load, a privileged user supplies a cache device whose superblock contains a value called seg_num. That value is used to size an array that bounds future segment identifiers, but it is not validated against the device’s actual capacity. When a segment id beyond the mapping range is accessed, the kernel performs a 12 KiB memset that writes past the end of the mapped device into arbitrary kernel heap memory. This out‑of‑bounds write (CWE‑787) corrupts kernel memory and can lead to arbitrary code execution with root privileges.
Affected Systems
All Linux kernel builds that include the dm‑pcache module are potentially impacted; no specific release versions are listed in the advisory. The flaw exists in every distribution that ships a kernel version containing the affected pcache code path.
Risk and Exploitability
The CVSS score of 5.7 indicates medium severity, while the EPSS score of < 1% suggests a low probability of exploitation. The bug requires CAP_SYS_ADMIN and can only be triggered locally. If exploited, heap corruption can lead to privilege escalation to root. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment