Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's IPv4 handling has been addressed. This issue involved a potential Spectre v1 vulnerability in the fib_metrics_match() function, where the 'type' variable could be misused as an array index. The flaw risked allowing CPU speculation to leak kernel memory contents. The vulnerability has been resolved by implementing measures to prevent such speculative execution.
Exploitation of this vulnerability could have led to unauthorized access to kernel memory, potentially allowing for information leakage.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.