Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's Multipath TCP (MPTCP) implementation has been addressed. The issue arose from the sysctl blackhole timeout feature, which improperly used the 'current' task's network namespace proxy. This approach could lead to inconsistencies and potential null pointer dereferences, particularly when the current task is exiting, as identified by syzbot. The vulnerability stemmed from relying on the 'net' structure through 'current', which can be NULL in certain situations.
Exploitation of this vulnerability could lead to a null pointer dereference, causing a kernel crash.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.