CVE-2026-53061

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/06/2026
Last modified:
21/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> dm cache: fix dirty mapping checking in passthrough mode switching<br /> <br /> As mentioned in commit 9b1cc9f251af ("dm cache: share cache-metadata<br /> object across inactive and active DM tables"), dm-cache assumed table<br /> reload occurs after suspension, while LVM&amp;#39;s table preload breaks this<br /> assumption. The dirty mapping check for passthrough mode was designed<br /> around this assumption and is performed during table creation, causing<br /> the check to fail with preload while metadata updates are ongoing. This<br /> risks loading dirty mappings into passthrough mode, resulting in data<br /> loss.<br /> <br /> Reproduce steps:<br /> <br /> 1. Create a writeback cache with zero migration_threshold to produce<br /> dirty mappings<br /> <br /> dmsetup create cmeta --table "0 8192 linear /dev/sdc 0"<br /> dmsetup create cdata --table "0 131072 linear /dev/sdc 8192"<br /> dmsetup create corig --table "0 262144 linear /dev/sdc 262144"<br /> dd if=/dev/zero of=/dev/mapper/cmeta bs=4k count=1 oflag=direct<br /> dmsetup create cache --table "0 262144 cache /dev/mapper/cmeta \<br /> /dev/mapper/cdata /dev/mapper/corig 128 2 metadata2 writeback smq \<br /> 2 migration_threshold 0"<br /> <br /> 2. Preload a table in passthrough mode<br /> <br /> dmsetup reload cache --table "0 262144 cache /dev/mapper/cmeta \<br /> /dev/mapper/cdata /dev/mapper/corig 128 2 metadata2 passthrough smq 0"<br /> <br /> 3. Write to the first cache block to make it dirty<br /> <br /> fio --filename=/dev/mapper/cache --name=populate --rw=write --bs=4k \<br /> --direct=1 --size=64k<br /> <br /> 4. Resume the inactive table. Now it&amp;#39;s possible to load the dirty block<br /> into passthrough mode.<br /> <br /> dmsetup resume cache<br /> <br /> Fix by moving the checks to the preresume phase to support table<br /> preloading. Also remove the unused function dm_cache_metadata_all_clean.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 3.13 (including) 5.10.258 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.209 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 6.1.175 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.141 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.91 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.33 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.10 (excluding)