Impact
The vulnerability lies in the Linux kernel’s dm‑io subsystem, where the do_region() routine incorrectly rebuilds destination bio structures for DM_IO_BIO requests by iterating over each page of the source bio and performing sector‑based accounting. When a direct I/O buffer is misaligned, the sector conversion discards a sub‑sector fragment, causing an infinite loop that submits empty bio requests. This results in an I/O hang that stalls operations on the affected DM_i‑mirror device, preventing legitimate processes from accessing the block device until the kernel is restarted or the device is removed. The fix removes the manual page copy path and simply clones the source bio’s biovec with bio_alloc_clone, eliminating the loop. The flaw applies to any Linux kernel binary that includes the device‑mapper dm‑mirror target and the unstable dm‑io implementation. Because the description does not list a specific kernel version, all kernels shipping with the unpatched code are potentially affected. The relation is captured by the generic CPE for the Linux kernel. The CVSS score of 4.1 indicates a low‑severity denial‑of‑service impact confined to the I/O subsystem. The EPSS score is less than 1 %, suggesting a very low likelihood of real‑world exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need the ability to issue misaligned direct I/O requests to a dm‑mirror target, which normally requires local execution or higher privilege. Thus the attack surface is limited to environments where such I/O operations are permitted, and the exploitation path is generally restricted to local or privileged users.
Affected Systems
The affected product is the Linux kernel integral to operating systems that use the device‑mapper dm‑mirror target and the dm‑io subsystem. All kernel releases that contain the unpatched code are potentially affected, and no specific version range is listed in the CNA data.
Risk and Exploitability
Because the flaw manifests as an infinite loop of empty BIO submissions when a misaligned direct‑I/O buffer is used with a dm‑mirror target, the primary consequence is a local denial of service that stalls I/O operations. The CVSS score of 4.1 reflects this low‑severity impact. The EPSS score of less than 1 % indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need the ability to issue misaligned O_DIRECT requests to a dm‑mirror device, generally requiring local or privileged execution. Thus the risk to systems exposed to such I/O patterns is low but could affect mission‑critical applications if the kernel is unpatched.
OpenCVE Enrichment