Impact
The flaw exists in the Linux DM PCACHE subsystem, where the kernel accepts cache segment identifiers from persistent metadata without validating them against the number of initialized segments. An attacker with CAP_SYS_ADMIN who supplies a malicious cache device can cause the kernel to index past the end of the segments array, resulting in out-of-bounds reads and writes. This can corrupt kernel memory, leading to denial of service or privilege escalation.
Affected Systems
All Linux kernel implementations that include the DM PCACHE module before the patch that adds cache_seg_id_valid() are affected. Systems that have not yet applied the kernel update are vulnerable.
Risk and Exploitability
The CVSS base score of 7.8 indicates high severity, while the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires CAP_SYS_ADMIN privileges to load a cache device, limiting the pool of capable attackers.
OpenCVE Enrichment