Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
An integer overflow vulnerability has been addressed in the Linux kernel's NTFS3 filesystem module. The issue arose in the 'hdr_first_de()' function, where the 'de_off' and 'used' variables, sourced from the disk, were not properly validated. On 32-bit systems, if both variables exceeded UINT_MAX - 16, the lack of appropriate checks led to an integer overflow, potentially causing unexpected behavior or exploitation.
Exploitation of this vulnerability could lead to incorrect memory handling, allowing for potential memory corruption or other unintended consequences.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.