Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's memory cgroup (memcg) implementation can lead to a NULL pointer dereference. This issue arises when the kernel's hwpoison feature forcibly uncharges a least recently used (LRU) hwpoisoned page. In such cases, the associated memory cgroup can be NULL, causing the 'mem_cgroup_track_foreign_dirty_slowpath()' function to dereference a NULL pointer. The vulnerability has been addressed by ensuring that foreign writebacks are not recorded for folios with a NULL memory cgroup.
Exploitation of this vulnerability leads to a NULL pointer dereference, causing a kernel crash.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.