Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's s390/pci subsystem has been addressed. The issue arose because the zpci_create_device() function returns an error pointer that must be checked before it is used as a struct zpci_dev pointer. The missing error check was added in the __clp_add() function, where the device was not properly added to the scan list. This omission could lead to the device being incorrectly managed, allowing for potential exploitation or instability.
The vulnerability could cause improper device management in the s390/pci subsystem, potentially leading to system instability or exploitation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.