Impact
The dm-integrity subsystem in the Linux kernel contained a flaw that allowed a user with raw write access to a backing device to forge a discard‑block tag. By writing a block whose tag consists entirely of 0xf6 bytes, the kernel treats the block as ‘discarded’ and skips HMAC verification, even though the attacker does not possess the integrity key. This bypass undermines the integrity protection mechanism, allowing arbitrary data to be accepted as authenticated.
Affected Systems
All Linux kernel implementations that include the dm-integrity module and which accept the allow_discards flag in standalone mode are affected. Because no concrete version range is listed, any kernel that has not incorporated the patch referenced by the commit series is vulnerable. The flaw applies to the generic Linux image and to distributions that ship with dm-integrity enabled.
Risk and Exploitability
The EPSS score of less than 1% and the lack of a listing in the CISA KEV catalog indicate that current exploitation is considered unlikely. Nevertheless, the vulnerability permits a local attacker with write privileges on a block device to subvert data integrity, which can lead to significant damage if leveraged. The attack vector is local and requires privileged or otherwise trusted access to the underlying storage device; it does not pose a network‑based threat.
OpenCVE Enrichment