Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's ACRN hypervisor component has been addressed, which could lead to information leakage. The issue arose in the 'pmcmd_ioctl' function, where three memory objects allocated by kmalloc were not properly initialized before being copied to user space. This lack of initialization created a risk of unintentional data exposure, as the uninitialized bytes could contain sensitive information.
Exploitation of this vulnerability could result in unauthorized information disclosure, allowing an attacker to access sensitive data that should not be available.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.