Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's ISP1760 USB driver has been identified, involving an out-of-bounds array access. This issue arises because the driver expects certain arrays to be a minimum length, but the arrays in question are dynamically sized during compilation. The vulnerability was detected using the Kernel Address Sanitizer, which reported a global out-of-bounds read by the 'swapper' task.
Exploitation of this vulnerability leads to a global out-of-bounds array access, which can potentially be exploited to overwrite memory and cause undefined behavior in the kernel.
The vulnerability has been addressed by modifying the array definitions to prevent out-of-bounds access. Users should upgrade to the latest version of the Linux kernel where this fix has been applied.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.