Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's ksmbd component was introduced during the parsing of security descriptors. The issue arises because offsets could exceed the size of the security descriptor structure, leading to a slab-out-of-bounds condition. Additionally, the validation of security identifiers (SIDs) did not properly account for the size of the sub-authority array.
Exploitation of this vulnerability could lead to a slab-out-of-bounds condition, potentially allowing for memory corruption or other unintended behavior.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.