Impact
The Linux kernel block subsystem fails to validate that user‑space I/O vectors are aligned to the device’s DMA. When a caller supplies a misaligned vector, the kernel previously accepted the vector and later detected the misalignment during bio handling, which could lead to data corruption or kernel panic. The fix adds input validation that checks the alignment against the device’s dma_alignment during bio construction, rejecting misaligned vectors early with an -EINVAL error.
Affected Systems
All Linux kernel releases prior to the commit that introduced the alignment validation are vulnerable. The flaw exists in every block driver that accepts user‑space vectors, so any system running an earlier kernel version, regardless of vendor or distribution, is affected.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and the EPSS score of < 1 % suggests a low probability of exploitation. Based on the description, it is inferred that an attacker who can invoke block operations from user space could provide a misaligned I/O vector, causing the kernel to reject the request with -EINVAL. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment