Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A data-race vulnerability has been identified in the Linux kernel's handling of the sysctl_fwmark_reflect variable. This vulnerability arises because the variable can be modified concurrently while it is being read, creating a potential for inconsistent or unexpected behavior. The issue has been addressed by adding a READ_ONCE() directive to the variable's reader, ensuring that reads are properly synchronized and reducing the risk of concurrent modification issues.
Exploitation of this vulnerability could lead to a data race condition, where concurrent operations on the sysctl_fwmark_reflect variable could cause unpredictable behavior in the kernel's processing of firewall marks. This could potentially be exploited to manipulate network traffic handling or introduce instability in the system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.