Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
dm-pcache: detect a cycle in the last-kset chain during replay
cache_replay() follows the on-media last-kset chain by next_cache_seg_id with no cond_resched(). A forged chain that points back into a segment it has already visited makes the replay loop follow it forever.
Cap the last-kset hops at cache->n_segs; a valid chain visits each segment at most once.
Details
- Affected product:
- Debian 10 ELS , Debian 11 ELS
- Affected packages:
- linux @ 4.19.0 (+1 more)