Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's arm64 architecture has been addressed, concerning the user-access non-executable (UXN) setting on swapper page tables. Systems implementing the FEAT_EPAN feature were affected because read/write access to the idmap was improperly allowed, leading to kernel panics when certain idmap KPTI mappings were accessed. The issue arose because UXN was not applied to the swapper page table entries, allowing unauthorized access. The vulnerability has been resolved by correctly setting the UXN attribute on these page table entries.
Exploitation of this vulnerability could lead to kernel panics, causing system instability and potential denial of service.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.