Impact
The bug is triggered when dmirror_fault() is called after a missing device page table entry. If the mirrored mm has already exited, mmget_not_zero() fails, but the code returns 0, telling the caller that the fault succeeded. The caller retries the same address, hits -ENOENT again, and can loop forever. Returning -EFAULT instead would cause the ioctl to fail, preventing the endless loop. As a result, the system can hang, leading to a denial of service for processes that depend on the mirrored device.
Affected Systems
All Linux kernel releases that include the vulnerable dmirror_fault implementation, as indicated by the kernel CPE entry. The fault exists in any kernel image that has not incorporated the recent patch referenced by the commit list.
Risk and Exploitability
The EPSS score is reported as less than 1%, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local or privileged user able to trigger kernel read/write operations on a device using the dmirror feature. No public exploit is known, but the infinite retry loop is a classic denial of service vector that can disrupt kernel operations.
OpenCVE Enrichment
Debian DLA
Debian DSA