Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A resource leak vulnerability has been identified in the Linux kernel's Netronome NFP driver. When devices are moved between namespaces, multicast addresses are removed from software management but remain in the application firmware, leading to a resource leak. The vulnerability affects the Linux kernel stable tree. The issue has been addressed by modifying the driver to use the '__dev_mc_unsync' function to properly clean up multicast addresses in the firmware when a port is closed.
The vulnerability can lead to a resource leak by not properly cleaning up multicast addresses in application firmware, potentially causing issues related to resource management and availability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.