Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability allowing integer overflows has been identified in the Linux kernel's Marvell OCTEON TX crypto driver. This issue arises from the 'code_length' value sourced from firmware files, which, if untrusted, can lead to potential exploitation. The vulnerability affects the stable versions of the Linux kernel.
Exploitation of this vulnerability could lead to undefined behavior in the kernel, potentially allowing for memory corruption or other malicious actions.
The vulnerability can be reproduced by loading a firmware file into the Marvell OCTEON TX crypto driver that contains a 'code_length' value designed to cause an overflow. This can be done by manipulating the firmware file to include an excessively large 'code_length' value, which the driver will not properly validate before use.
Users can update to the latest version of the Linux kernel, where this vulnerability has been fixed. Instructions for updating the kernel can be found in the official Linux kernel documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.