Linux Kernel TIPC Subsystem Uninitialized Value Vulnerability in Netlink Compatibility

Vulnerability

A vulnerability has been identified in the Linux kernel's TIPC (Transparent Inter-Process Communication) subsystem, specifically within the netlink compatibility layer. This issue arises from improper handling of message length checks, which can lead to the use of uninitialized values. The vulnerability was reported by syzbot, highlighting a call trace that reveals the uninitialized value issue during the processing of name table dump headers.

Impact

Exploitation of this vulnerability can lead to the use of uninitialized values, which may cause undefined behavior in the kernel, potentially allowing for memory corruption or other malicious actions.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.