Executive brief
The Linux kernel's dm-pcache module is a persistent cache storage driver that manages on-disk cache metadata. An attacker with administrative privileges (CAP_SYS_ADMIN) who supplies a malicious cache device can craft metadata with unbounded key counts and offsets, causing the kernel to read past allocated buffer boundaries and leak adjacent persistent memory to user space via read operations.
Technical details
The vulnerability consists of two unbounded metadata fields in dm-pcache: (1) the kset key_num field is read without bounds-checking before use in cache_kset_crc() and cache_replay(), allowing reads past the PCACHE_KSET_KEYS_MAX buffer; (2) in cache_key_decode(), a key's intra-segment offset and length are taken verbatim without validation, allowing keys to specify data ranges extending past their segment boundaries. Both fields are sourced from attacker-supplied cache device metadata. The second flaw results in out-of-bounds reads of persistent memory that are subsequently copied to user-space buffers during cache hits. The fix introduces kset_onmedia_valid() to bound key_num before any metadata read, and validates that a key's offset plus length does not exceed segment data_size. Requires CAP_SYS_ADMIN to exploit.
Affected products
- Linux Linux kernel dm-pcache module (introduced in commit 1d57628ff95b)
Timeline
- 2026-09-11: disclosed
- 2026-09-07: patched: Patch merged to stable kernels via commits 5ac38f4b and d8caf960