Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's ksmbd component was introduced by an unchecked addition in the dacloffset field, originally typed as int. This oversight allowed the addition to overflow, potentially bypassing existing bounds checks in the smb_check_perm_dacl() and smb_inherit_dacl() functions. The overflow could lead to out-of-bounds memory access, causing a kernel crash when the DACL pointer was dereferenced.
Exploitation of this vulnerability could lead to out-of-bounds memory access, causing a kernel crash.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.