Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
An integer overflow vulnerability has been identified in the Linux kernel's CIFS (Common Internet File System) implementation. This issue arises when the user-provided mount parameter 'closetimeo', which is of type u32, is converted from seconds to jiffies without proper validation. The lack of validation allows for the possibility of an integer overflow. The vulnerability affects several versions of the Linux kernel.
Exploitation of this vulnerability can lead to an integer overflow, which may be leveraged to cause unexpected behavior in the system, such as memory corruption or arbitrary code execution.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.