Executive brief
The Linux kernel's device mapper (dm) component incorrectly attempts to queue IO operations while holding RCU read locks, which can trigger kernel warnings and system instability. An unprivileged user can exploit this by issuing direct IO read operations with the NOWAIT flag, causing the kernel to attempt scheduling operations that violate locking constraints, leading to potential system crashes or service disruption.
Technical details
The vulnerability is a locking violation in the device mapper's dm_submit_bio() function. The code assumes that IO requests marked with REQ_NOWAIT (non-blocking) can be submitted while under RCU read lock protection; however, REQ_NOWAIT only prevents sleeping on other IO operations, not scheduling. When processing direct IO with preadv2() and RWF_NOWAIT, the code path calls bio_alloc_clone() which invokes mempool_alloc(), a function that may trigger memory reclamation and rescheduling—operations forbidden under RCU locks. This triggers a BUG warning: "sleeping function called from invalid context." The attack vector is local and unprivileged, requiring only the ability to open a device mapper device and issue a crafted preadv2() syscall. No authentication or special privileges are required.
Affected products
- Linux Linux kernel Up to and including 6.6.0-rc1
Timeline
- 2023: disclosed: Vulnerability resolved in Linux kernel commit