Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) implementation has been addressed. The issue arose from the 'auth_enable' sysctl using 'current->nsproxy', which can lead to inconsistencies and potential null pointer dereferences. This vulnerability was identified by syzbot, particularly when the current task is exiting. The problem stems from accessing the 'net' structure through 'current', which is not advisable for various reasons, including the possibility of 'current->nsproxy' being NULL in certain situations.
Exploitation of this vulnerability could lead to a null pointer dereference, causing a kernel crash.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.