Impact
The Linux kernel device‑mapper array module performs limited validation in array_block_check, accepting block numbers and checksums while ignoring structural limits on entry counts. When dm_array_cursor_next calculates its loop bound from an on‑disk field that exceeds a block’s actual capacity, element_at performs unchecked pointer arithmetic. This allows a read to traverse beyond the dm‑bufio buffer and access kernel memory or trigger a kernel crash, exposing sensitive data or causing service interruption.
Affected Systems
Linux kernel instances that include the dm‑array module and are running a version prior to the applied patch are affected. The vulnerability is independent of distribution and affects any installation where the dm‑array subsystem is enabled and the kernel code has not been updated to contain the header‑validation fix.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score of < 1% and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require local or privileged access that can manipulate DM array blocks or load the device‑mapper subsystem. No public exploit has been reported; the attack vector is inferred to be local privilege elevation or direct interaction with the dm‑array interface.
OpenCVE Enrichment
Debian DSA