Impact
The Linux kernel s390/dasd subsystem contains a flaw where a partially completed ERP request inadvertently loses its proc_bytes value during recovery. When the cleanup routine later interprets this zero value, it mistakenly treats the entire request as complete and zero‑fills any remaining unread data. The result is silent corruption of data read from DASD devices, compromising data integrity without triggering error codes or crashes.
Affected Systems
The vulnerability affects the s390 DASD driver within the Linux kernel. Any system running a kernel version that contains the unpatched code path and that relies on the default s390 kernel is potentially at risk. No specific version range is listed, so all affected releases lacking the fix should be considered vulnerable.
Risk and Exploitability
The CVSS score of 7.0 indicates moderate to high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the ability to trigger ERP operations on a DASD device, so widespread abuse remains limited. However, environments that allow untrusted users to issue reads on DASD devices face potential silent data corruption and loss of confidentiality or integrity.
OpenCVE Enrichment
Debian DSA