Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) implementation has been addressed. The issue arose from the sysctl interface for the cookie HMAC algorithm, which improperly used the 'current' task's namespace proxy. This approach could lead to inconsistencies by mixing network namespace information from different tasks, and it also posed a risk of null pointer dereference errors when the current task was exiting. The vulnerability was identified by syzbot.
Exploitation of this vulnerability could lead to a null pointer dereference, causing a kernel crash.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.