dm-pcache: validate the persisted dirty_tail chain at load
Summary
| CVE | CVE-2026-93198 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 17:18:16 UTC |
| Updated | 2026-09-17 17:18:16 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate the persisted dirty_tail chain at load The writeback worker follows the persisted dirty_tail chain, which is decoded from the cache device independently of the key_tail chain that cache_replay() walks and bounds. A crafted image, whose on-media fields are authenticated only by a crc32c with a fixed seed, can aim dirty_tail at a chain of last ksets that never terminates, so cache_writeback_fn() re-arms itself with no delay forever. Walk the dirty_tail chain once at load with the same hop cap cache_replay() uses and fail the table load with -EIO if it does not reach an end within n_segs hops. |
Risk And Classification
EPSS: 0.001840000 probability, percentile 0.082900000 (date 2026-09-19)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 8195cf3f4a82ef49d9b0651c507ed0784caf23fb git | Not specified |
| CNA | Linux | Linux | affected 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 4822a030929e0e77aa380722dc42e3e4c9edd346 git | Not specified |
| CNA | Linux | Linux | affected 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 58d620ee9e01d4bdbceaf2ae1450d307a2a9d58b git | Not specified |
| CNA | Linux | Linux | affected 6.18 | Not specified |
| CNA | Linux | Linux | unaffected 6.18 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.52 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.6 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/58d620ee9e01d4bdbceaf2ae1450d307a2a9d58b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/8195cf3f4a82ef49d9b0651c507ed0784caf23fb | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/4822a030929e0e77aa380722dc42e3e4c9edd346 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.