Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) sysctl interface for minimum and maximum retransmission timeouts has been addressed. The issue arose from using the 'net' structure via 'current', which can lead to inconsistencies and potential null pointer dereferences. This vulnerability was identified by syzbot while using the acct system call.
Exploitation of this vulnerability could lead to a null pointer dereference, causing a kernel crash.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.