Impact
The dm‑pcache subsystem contains a flaw where the kset key_num field and the intra‑segment offset and length are not bounded before use. A malicious cache device crafted by a user with CAP_SYS_ADMIN causes the kernel to read past the end of the key bio. This out‑of‑bounds read can leak any data that resides in the kernel’s memory space, making it a high‑severity information‑disclosure vulnerability (CWE‑125).
Affected Systems
All Linux kernel releases that include the dm‑pcache code without the bounds‑check patch are affected. The CNA only lists generic Linux kernel entries, so any distribution relying on an unpatched kernel may be vulnerable; no specific version range is provided, and thus all kernels containing this code should be treated as potentially impacted until the fix is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity level, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV. The likely attack vector is a local user possessing CAP_SYS_ADMIN who supplies a malicious cache device to the kernel; the need for local privileged access limits the threat surface to compromised or trusted accounts.
OpenCVE Enrichment