Impact
In the Linux dm-era module, a failure in the snapshot creation process causes the kernel to bump the live superblock reference count and allocate a shadow block, but if the subsequent allocation of that shadow block fails, the block is never returned to the metadata space map. The result is a permanent leak of one metadata block, which can accumulate and consume kernel resources over time.
Affected Systems
All Linux systems that use the dm-era device‑mapper target and run a kernel version prior to the fix are potentially affected. Any distribution shipping the unpatched kernel in its standard repositories contains this flaw until the patch is included.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity, while the EPSS score of < 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need local privilege or kernel code execution to repeatedly trigger snapshot failures. Because the leak only occurs on failure, a rapid real-world exploitation scenario is unlikely, although repeated failures could eventually exhaust metadata blocks and degrade kernel availability.
OpenCVE Enrichment
Debian DSA