Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's DCP trusted keys handling can lead to a crash during the encryption and decryption of blob encryption keys. This issue arises when vmalloc stack addresses are enabled, causing the DCP crypto driver to improperly manage stack buffers allocated with vmalloc. The vulnerability has been addressed by ensuring that the DCP crypto driver only receives buffers allocated with kmalloc.
The vulnerability can cause a kernel crash, disrupting system operations and potentially leading to a denial of service.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.