Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's arm64 architecture has been addressed, concerning the user-execution never (UXN) setting on swapper page tables. Systems implementing FEAT_EPAN were affected because read/write access to the idmap was improperly allowed, leading to kernel panics when certain idmap KPTI flags were accessed. The issue arose because UXN was not applied to the swapper page table entries, allowing unauthorized access. The vulnerability has been resolved by correctly setting the UXN on these entries.
The vulnerability could cause kernel panics, disrupting system operations and potentially leading to denial of service conditions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.