Linux Kernel ICMP Sysctl Data-Race Vulnerability

Vulnerability

A data-race vulnerability has been identified in the Linux kernel's ICMP implementation, specifically related to sysctl variables. When these variables are read, they can be concurrently modified, leading to potential inconsistencies. To address this issue, the kernel has been updated to include a READ_ONCE() directive, which helps prevent such data-races.

Impact

Exploitation of this vulnerability could lead to data inconsistencies and unpredictable behavior in the ICMP protocol handling within the kernel.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
5.0
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.