Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability has been identified in the Linux kernel's USB networking driver for the smsc95xx chip. This issue arises because the packet length retrieved from the descriptor can exceed the actual length of the socket buffer. As a result, when the cloned socket buffer is passed up the network stack, it can inadvertently leak contents of kernel memory.
Exploitation of this vulnerability leads to unauthorized disclosure of kernel memory contents.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.