CVE-2026-53063
Received Received - Intake
dm-cache Write Hang Vulnerability in Linux Kernel

Publication date: 2026-06-24

Last updated on: 2026-06-24

Assigner: kernel.org

Description
In the Linux kernel, the following vulnerability has been resolved: dm cache: fix write hang in passthrough mode The invalidate_remove() function has incomplete logic for handling write hit bios after cache invalidation. It sets up the remapping for the overwrite_bio but then drops it immediately without submission, causing write operations to hang. Fix by adding a new invalidate_committed() continuation that submits the remapped writes to the cache origin after metadata commit completes, while using the overwrite_endio hook to ensure proper completion sequencing. This maintains existing coherency. Also improve error handling in invalidate_complete() to preserve the original error status instead of using bio_io_error() unconditionally.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-24
Last Modified
2026-06-24
Generated
2026-06-25
AI Q&A
2026-06-24
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the Linux kernel's device mapper cache (dm cache) subsystem, specifically in passthrough mode. The issue is caused by incomplete logic in the invalidate_remove() function when handling write hit bios after cache invalidation. The function sets up remapping for the overwrite_bio but then drops it immediately without submitting it, which causes write operations to hang.

The fix involves adding a new continuation function, invalidate_committed(), which submits the remapped writes to the cache origin after the metadata commit completes. It also uses the overwrite_endio hook to ensure proper completion sequencing and improves error handling to preserve the original error status.

Impact Analysis

This vulnerability can cause write operations to hang in the Linux kernel's dm cache passthrough mode. This means that data writes may not complete properly, potentially leading to system instability, degraded performance, or data loss if write operations are indefinitely stalled.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53063. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart