Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
An integer overflow vulnerability has been identified in the Linux kernel's handling of socket options for the ROSE protocol. This issue arises in the 'rose_setsockopt()' function, where large arguments can be unpredictably passed and multiplied by additional values, leading to potential overflows. The vulnerability affects several versions of the Linux kernel.
Exploitation of this vulnerability could lead to integer overflow, which may be leveraged to cause buffer overflows or other unintended behavior in the kernel.
The vulnerability has been addressed in the official Linux kernel repository. Users should upgrade to the latest version where this issue has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.