Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A NULL pointer dereference vulnerability has been identified in the Linux kernel's etas_es58x driver. The issue arises because the driver incorrectly assumed that the USB serial number would never be NULL. While this assumption holds true for commercially available devices, an attacker could potentially spoof the device identity to provide a NULL serial number, leading to a NULL pointer dereference. The vulnerability has been addressed by adding a check for the serial number before accessing it.
Exploitation of this vulnerability could lead to a system crash or undefined behavior due to the NULL pointer dereference.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.