Impact
The vulnerability resides in the Linux kernel's device‑mapper module. When a user‑space process issues two overlapping dm_setup_md_queue ioctl calls—one that succeeds and one that fails—the kernel walks the dm->table_devices list without holding an appropriate lock. Concurrently, dm_table_destroy may free the list entries, causing the walk to touch freed memory. This race can corrupt memory or crash the kernel, leading to service disruption.
Affected Systems
Affected systems are all devices running the Linux kernel with the device‑mapper component. The advisory does not specify a precise kernel version; any kernel incorporating the unsynchronized table walk paths is susceptible. It applies broadly to Linux distributions that ship the standard kernel.
Risk and Exploitability
The CVSS score of 7.8 classifies this as high severity. EPSS <1% indicates a low probability that attackers will target this flaw. It is not listed in CISA’s KEV catalog, suggesting limited exploitation activity so far. The flaw requires elevated privileges to perform the counter‑opposed ioctl calls, so the attack vector is local. Despite the low exploitation likelihood, the potential to crash the kernel or cause memory corruption warrants a prompt patch.
OpenCVE Enrichment
Debian DLA
Debian DSA