Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +3 more
A vulnerability in the Linux kernel's management of ECC (Error Correction Code) for certain Winbond NAND flash chips has been addressed. The affected chips include the W25N512GW, W25N01GW, W25N01JW, and W25N02JW, all of which require a single bit of ECC strength and have an on-die Hamming-like ECC engine. Previously, the kernel issued a warning for unnecessary ECC status queries, as the main ECC status bytes are located in standard positions and the chips only support reporting a maximum of one bit flip in corrected data. This vulnerability could lead to misleading kernel warnings about ECC bit flips that are not indicative of a larger issue.
The vulnerability could cause unnecessary kernel warnings about ECC bit flips for the affected NAND flash chips, potentially leading to confusion or misinterpretation of the chip's error correction status.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.