Impact
The dm‑io driver in the Linux kernel handled BLK_STS_NOTSUPP and BLK_STS_INVAL status codes as fatal, causing the dm‑raid1 device‑mapper module to fail an entire mirrored leg when these non‑retryable errors were reported. This logic flaw can lead to loss of redundancy for a dm‑raid1 array and interrupt service when unaligned I/O vectors are used.
Affected Systems
All Linux kernel releases containing the dm‑raid1 component before the commit that split error reporting are vulnerable. This includes most mainstream distributions with kernels older than the commit that introduced separate error bitmaps. The fix is present in kernels containing that commit, so systems running newer kernels are not affected.
Risk and Exploitability
The vulnerability requires an attacker to trigger the legacy error path, which typically necessitates local or privileged access to create unaligned bio vectors. The EPSS score is below 1 % and it is not listed in the CISA KEV catalog, indicating a low exploitation likelihood. Without a publicly defined CVSS score, the severity appears focused on availability rather than confidentiality or integrity.
OpenCVE Enrichment