Impact
A flaw in the Linux kernel’s dm-pcache module incorrectly validates a persisted dirty_tail chain when a device image is loaded. An attacker can craft an image whose on‑media fields are authenticated only by a simple CRC checksum, directing the writeback worker to follow a dirty_tail chain that never terminates. The worker repeatedly re‑arms itself with no delay, causing an infinite loop that consumes CPU cycles until the kernel can recover, effectively degrading or halting system responsiveness.
Affected Systems
The affected component is the Linux kernel’s dm‑pcache subsystem. All distributions that ship with dm‑pcache enabled in the kernel are potentially impacted, regardless of the specific vendor distribution, as the module code is part of the core kernel image.
Risk and Exploitability
The exploit requires the ability to load a malicious dm‑pcache image, which typically requires root or privileged access to the block device backing the cache. Because the flaw is local and does not allow arbitrary code execution, the risk is confined to denial of service. The EPSS score is below 1 %, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. If compromised, an attacker could force the kernel to enter a high‑CPU loop, potentially leading to system unavailability.
OpenCVE Enrichment