« Volver al listado

CVE-2026-93198

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

dm-pcache: validate the persisted dirty_tail chain at load

The writeback worker follows the persisted dirty_tail chain, which is decoded from the cache device independently of the key_tail chain that cache_replay() walks and bounds. A crafted image, whose on-media fields are authenticated only by a crc32c with a fixed seed, can aim dirty_tail at a chain of last ksets that never terminates, so cache_writeback_fn() re-arms itself with no delay forever.

Walk the dirty_tail chain once at load with the same hop cap cache_replay() uses and fail the table load with -EIO if it does not reach an end within n_segs hops.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93198",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "1d57628ff95b32d5cfa8d8f50e07690c161e9cf0",
              "lessThan": "8195cf3f4a82ef49d9b0651c507ed0784caf23fb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1d57628ff95b32d5cfa8d8f50e07690c161e9cf0",
              "lessThan": "4822a030929e0e77aa380722dc42e3e4c9edd346",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1d57628ff95b32d5cfa8d8f50e07690c161e9cf0",
              "lessThan": "58d620ee9e01d4bdbceaf2ae1450d307a2a9d58b",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/md/dm-pcache/cache.c",
            "drivers/md/dm-pcache/cache.h",
            "drivers/md/dm-pcache/cache_key.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.18"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.18",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/md/dm-pcache/cache.c",
            "drivers/md/dm-pcache/cache.h",
            "drivers/md/dm-pcache/cache_key.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:18:16.097",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/4822a030929e0e77aa380722dc42e3e4c9edd346",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/58d620ee9e01d4bdbceaf2ae1450d307a2a9d58b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8195cf3f4a82ef49d9b0651c507ed0784caf23fb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-pcache: validate the persisted dirty_tail chain at load\n\nThe writeback worker follows the persisted dirty_tail chain, which is\ndecoded from the cache device independently of the key_tail chain that\ncache_replay() walks and bounds. A crafted image, whose on-media fields are\nauthenticated only by a crc32c with a fixed seed, can aim dirty_tail at a\nchain of last ksets that never terminates, so cache_writeback_fn() re-arms\nitself with no delay forever.\n\nWalk the dirty_tail chain once at load with the same hop cap cache_replay()\nuses and fail the table load with -EIO if it does not reach an end within\nn_segs hops."
    }
  ],
  "lastModified": "2026-09-17T17:18:16.097",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}