Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A data race vulnerability has been identified in the Linux kernel's TCP implementation, specifically regarding the sysctl_tcp_fastopen_blackhole_timeout parameter. This vulnerability allows the timeout value to be changed concurrently while it is being read, potentially leading to inconsistent behavior. The issue has been addressed by adding a READ_ONCE() directive to the parameter's readers, ensuring safe access and preventing concurrent modification.
Exploitation of this vulnerability could lead to data corruption or inconsistent behavior in TCP fast open operations, as concurrent reads and writes to the timeout parameter could cause race conditions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.