Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A data race vulnerability has been identified in the Linux kernel's TCP implementation, specifically regarding the sysctl_tcp_min_snd_mss parameter. This vulnerability arises because the parameter can be modified concurrently while it is being read, potentially leading to inconsistent or unexpected behavior. The issue has been addressed by adding a READ_ONCE() directive to the readers of this parameter, ensuring that reads are performed safely and consistently.
Exploitation of this vulnerability could lead to data corruption or inconsistent state in TCP connections, as concurrent modifications and reads of the sysctl_tcp_min_snd_mss parameter could interfere with normal TCP operation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.