Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) implementation has been addressed. The issue arose from the sysctl parameter 'plpmtud_probe_interval', which improperly used 'current->nsproxy' to access the 'net' structure. This approach could lead to inconsistencies and potential null pointer dereferences, particularly when the current task is exiting. The vulnerability was identified by syzbot, highlighting the need for a more reliable method of obtaining network namespace information.
The vulnerability could cause a null pointer dereference, leading to a kernel crash.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.