Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's BPF JIT (Just-In-Time) compilation process for x86_64 architecture has been addressed. The issue arose in the handling of BPF program packs, particularly when multiple subprograms were involved. During the JIT compilation, the kernel failed to properly free and finalize certain data, leading to a situation where an erroneous memory deallocation could occur. This flaw was reported by syzkaller and could potentially be exploited under specific conditions.
Exploitation of this vulnerability could lead to improper memory management, causing a 2MB memory page to be freed incorrectly, which could be exploited for memory corruption.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.