Executive brief
A vulnerability was identified in the Linux kernel's device-mapper cache component. When the system is configured in a specific 'passthrough' mode, multiple internal processes can attempt to update the same memory locations simultaneously without proper coordination. This can lead to system instability, data corruption in the cache metadata, or a system crash (use-after-free), potentially impacting the availability of storage services.
Technical details
A race condition exists in the 'smq' (Stochastic Multi-Queue) cache policy of the Linux kernel's Device Mapper (dm-cache). In passthrough mode, the 'invalidate_mapping' operation can be invoked simultaneously by multiple worker threads. Because the 'smq_invalidate_mapping' function lacked proper spinlock protection, concurrent execution leads to data races on the allocated blocks counter and potential use-after-free (UAF) conditions within internal data structures. An attacker with local access could potentially trigger this race through specific I/O patterns to cause a kernel oops or memory corruption. The issue has been resolved by adding 'spin_lock_irqsave' and 'spin_unlock_irqrestore' around the critical section in 'drivers/md/dm-cache-policy-smq.c'.
Affected products
- Linux Linux Kernel Versions using dm-cache with smq policy
Timeline
- 2026-02-09: other: Patch authored by Ming-Hung Tsai
- 2026-06-24: disclosed: CVE published
References
- https://git.kernel.org/stable/c/1b2bec4a7dcf5f00b7a1cbeeec8997841d783513
- https://git.kernel.org/stable/c/2b62d0611c9af14a16bddf22df2612b4f40eb5a1
- https://git.kernel.org/stable/c/2d1f7b65f5deedd2e6b09fdc6ea27f8375f24b45
- https://git.kernel.org/stable/c/4991b5a08751e2e82488fb93ae08849b6aea10d9
- https://git.kernel.org/stable/c/93627a29d4b66d4a2def938dfb8610cc80ae454b
- https://git.kernel.org/stable/c/9a5fdfb9e57ec3a8ad2b8fce5e5ffa42d53b130e
- https://git.kernel.org/stable/c/ac5ee99443891bdb161f5539606a66a1b5e72542