Executive brief
dm-pcache is a device-mapper persistent cache target that caches data to improve I/O performance. A use-after-free vulnerability in the cache key replay function can allow a local attacker to read or write kernel memory, potentially leading to privilege escalation or denial of service.
Technical details
The vulnerability is a use-after-free in the kset_replay() function within the dm-pcache device-mapper module. When a cache key's segment generation is stale (key->seg_gen < key->cache_pos.cache_seg->gen), the code calls cache_key_put(key) to free the key structure, but then immediately dereferences key->cache_pos.cache_seg in calls to cache_seg_get() and __set_bit(), accessing freed memory. Although mempool recycling delays reclamation in practice, this creates a potential UAF. The fix reorders operations to perform validity checks before these operations, ensuring cache_seg_get() and __set_bit() only execute on valid keys, and skips expired keys entirely.
Affected products
- Linux Linux kernel versions with dm-pcache module (Linux 5.x and later kernel versions)
Timeline
- 2026-07-20: other: Fix commit authored
- 2026-09-11: disclosed: Published in NVD
- 2026-09-07: patched: Stable kernel patch released