Impact
The vulnerability is a logic flaw in the Linux kernel’s RAID5 bitmap mapping routine, where sector ranges are rounded according to an incorrect stripe width calculation. This misalignment can cause write and read operations to target the wrong component disks, leading to corruption or loss of stored data. The bug originates from the use of integer division that fails to account for non‑power‑of‑two stripe widths, a flaw that can be classified under CWE‑680 (Integer Overflow or Wraparound) and CWE‑682 (Incorrect Calculation).
Affected Systems
All Linux kernel releases that implement the described raid5_bitmap_sector_map logic before the commit that corrects the rounding behavior are affected. The exact kernel version impacted is not specified in the provided data; any system running an unpatched kernel containing the flawed code is vulnerable.
Risk and Exploitability
The EPSS score is less than 1 %, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector requires local access with the ability to perform I/O on a RAID5 array, so it is an intrinsic local privilege scenario. Reliability of attacks is limited by the lack of publicly available exploitation code and the narrow requirements for the target, so the overall risk is low but should be mitigated promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA