Impact
The vulnerability arises when the dm‑pcache driver processes on‑disk metadata without proper bounds validation. When a cache device is loaded, the code reads the number of segments (n_segs) and the segment IDs from the metadata. If an attacker supplies an n_segs larger than the actual device segment count or a segment ID that falls outside the valid range, the driver accesses beyond the bounds of the cache->segments array, causing out‑of‑bounds reads and writes that can corrupt kernel memory. This memory corruption can lead to integrity compromise, privilege escalation, or a system crash, severely impacting confidentiality, integrity, and availability.
Affected Systems
No specific affected kernel version range is provided in the CVE data. The vulnerability is present in any Linux kernel that includes the dm‑pcache driver and has not applied the patch that validates cache geometry metadata on load. All systems that use dm‑pcache are potentially vulnerable until updated or the driver is disabled.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score of < 1% and the absence of a KEV listing suggest the likelihood of current exploitation is low. The exploit requires local capability to create or load a dm‑pcache table, so the attack vector is local. Vulnerable systems are those with dm‑pcache enabled; the potential impact includes memory corruption that can elevate privileges, corrupt data, or cause denial of service.
OpenCVE Enrichment