Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability leading to a potential NULL pointer dereference has been identified in the Linux kernel's ping subsystem. This issue arises in the /proc/net/icmp interface, where improper synchronization can occur. The vulnerability is present in versions of the Linux kernel that have adopted Read-Copy-Update (RCU) lookups for ping sockets, but failed to properly manage the associated concurrency controls, particularly for the ICMP netlink interface.
Exploitation of this vulnerability could lead to a NULL pointer dereference, causing a kernel crash or other undefined behavior.
Users can upgrade to the latest version of the Linux kernel to address this vulnerability. The specific commit that resolves this issue is available in the Linux kernel stable tree.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.