Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A shift-out-of-bounds vulnerability has been identified in the Linux kernel's memory compaction code. This issue arises in the 'isolate_freepages_block()' function, where the compound_order can be manipulated to any value due to its union with flags. The vulnerability triggers a Undefined Behavior Sanitizer (UBSAN) warning. The warning has been addressed by reinstating a maximum page order check.
Exploitation of this vulnerability could lead to undefined behavior in the kernel, potentially causing memory corruption or other unintended consequences.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.