Impact
This vulnerability in the Linux kernel’s dm-integrity subsystem arises from a buffer overrun caused by miscalculating buffer space when computing checksums for discarded blocks that use keyed sector markers. A discard operation can write beyond the bounds of an allocated page, resulting in memory corruption that may enable an attacker to execute arbitrary code within kernel context. The overflow occurs when the tag size is smaller than the digest size, with the checksum of the last block written past the allocated buffer.
Affected Systems
The flaw affects all Linux kernel builds that use the dm-integrity module prior to the patch that applied commit 68c5c42567bc. It applies to any system where the dm-integrity target device is enabled, regardless of distribution, as the vulnerability is identified at the kernel level. No specific vendor or product versions are listed, so any older kernel using dm-integrity is potentially impacted.
Risk and Exploitability
The CVSS score is 7.8, indicating high severity; the buffer overflow nature indicates a high likelihood of privilege escalation or arbitrary code execution. The EPSS score is less than 1%, indicating a low estimate of exploitation probability at this time, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires a discard operation on a dm-integrity-enabled device, the likely attack vector is local exploitation through privileged or root-level access to the block device.
OpenCVE Enrichment