Impact
In the Linux kernel, a race condition exists between the resume and remove ioctl operations for device mapper devices. If a resume request is handled concurrently with a remove request, the device may be resumed after the kernel starts destroying its context. This results in the dm_table being freed without calling the required postsuspend callback. Device mapper targets that expect that callback can misbehave, such as the dm-integrity target leaving a reboot notifier registered, which can cause a use‑after‑free when the system reboots. The flaw is a classic use‑after‑free in kernel memory and could allow a privileged attacker to crash the system or execute code with kernel privileges.
Affected Systems
The affected product is the Linux kernel. All kernel releases that omit the commit that introduces the dm: fix resume‑vs‑remove race patch are vulnerable. Because the vulnerability is triggered by the interaction of two privileged ioctl calls, any system running an unpatched kernel is at risk where a local user with permission to issue device mapper ioctl operations could trigger the race.
Risk and Exploitability
The CVSS score of 7.8 places the flaw in the high severity range. The EPSS score indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation is best‑effort and requires a local attacker who can perform the two ioctl calls concurrently, likely at privileged level. Once the race is exploited, the use‑after‑free can lead to a kernel crash or privilege escalation, thereby raising the impact if the attacker gains a foothold.
OpenCVE Enrichment
Debian DLA
Debian DSA