Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability allowing out-of-bounds writes has been identified in the Linux kernel's ath5k wireless driver. This issue arises in the 'ath5k_eeprom_read_pcal_info_5111' function, where the index can exceed the expected range, leading to memory corruption. The vulnerability was discovered through fuzzing, which revealed that when certain conditions are met, the index can go beyond the limit of available data curves, causing a write operation to an invalid memory address. This out-of-bounds write could be exploited to manipulate memory, potentially leading to arbitrary code execution or other malicious outcomes.
Exploitation of this vulnerability causes a slab-out-of-bounds memory write, which can lead to memory corruption and potentially allow for arbitrary code execution.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.