Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
- >= 6.0.0-rc2, < 6.0.0-rc3
A vulnerability in the Linux kernel's device-mapper cache implementation can lead to a kernel BUG due to improper memory management of background tracker work objects. When the background tracker is destroyed, any queued work is not correctly freed, causing objects to remain in the work queue. This issue was introduced in Linux version 6.0.0-rc2 by a commit that altered how kernel memory caches are managed, specifically regarding the deletion of objects without proper synchronization. The vulnerability was discovered using the LVM2 test suite.
Exploitation of this vulnerability can cause a kernel panic, where the system encounters a critical error and stops functioning, potentially leading to a denial of service.
The vulnerability can be reproduced by using the LVM2 test suite, specifically the 'cache-single-split.sh' script, which triggers the incomplete cleanup of the background tracker's work objects.
Users can upgrade to the latest stable version of the Linux kernel to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.