Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's RDS subsystem has been addressed, specifically related to the sysctl parameters rds_tcp_rcvbuf and rds_tcp_sndbuf. The issue arose from using the 'current' task's network namespace, which can lead to inconsistencies and potential null pointer dereferences, particularly when the current task is exiting. This vulnerability was identified by syzbot.
Exploitation of this vulnerability could lead to a null pointer dereference, causing a kernel crash.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.