Linux Kernel Sysctl Data-Race Vulnerability

Vulnerability

A data-race vulnerability has been identified in the Linux kernel's sysctl interface, specifically within the proc_dou8vec_minmax() function. This vulnerability arises because a sysctl variable can be accessed concurrently, leading to potential load/store tearing. Although proc_dou8vec_minmax() can currently tolerate such data-races, it requires additional annotations to address the issue properly. The vulnerability affects several versions of the Linux kernel.

Impact

Exploitation of this vulnerability could lead to data corruption or unpredictable behavior in the sysctl interface, allowing for concurrent read and write operations to interfere with each other.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
5.0
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.