Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A null pointer dereference vulnerability has been identified in the Linux kernel's Mobile Hotspot Interface (MHI) bus endpoint management. This issue arises because the channel disconnect status, -ENOTCONN, is sent even when the client driver is not available, leading to a null pointer dereference. The vulnerability is present in the stable versions of the Linux kernel.
Exploitation of this vulnerability causes a null pointer dereference, which can lead to a system crash or instability.
The vulnerability can be reproduced by sending STOP or RESET commands to an MHI endpoint when the client driver is not available. This will trigger the channel disconnect status -ENOTCONN, causing a null pointer dereference.
Users can upgrade to the latest stable version of the Linux kernel, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.