Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability has been identified in the Linux kernel's TIPC (Transparent Inter-Process Communication) subsystem, specifically within the netlink compatibility layer. This issue arises from improper handling of message length checks, which can lead to the use of uninitialized values. The vulnerability was reported by syzbot, highlighting a call trace that reveals the uninitialized value issue during the processing of name table dump headers.
Exploitation of this vulnerability can lead to the use of uninitialized values, which may cause undefined behavior in the kernel, potentially allowing for memory corruption or other malicious actions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.