Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A potential integer overflow vulnerability has been identified in the Linux kernel's Integrity Measurement Architecture (IMA) appraise feature. When the IMA module signature verification is enabled, a negative return code passed to the 'evm_verifyxattr()' function could lead to an integer overflow.
Exploitation of this vulnerability could result in an integer overflow, which may be leveraged to cause unexpected behavior in the kernel, potentially leading to memory corruption or other vulnerabilities that could be exploited.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.