Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's netfilter component, specifically in the nf_set_pipapo_avx2 function, has been addressed. The issue arose when the first field did not completely cover the initial map, leading to a leakage of uninitialized bits into the subsequent match round map. Although an early fix was applied, it only corrected the generic C implementation. A follow-up patch has been introduced to nft_concat_range.sh to add a test case for this scenario.
Exploitation of this vulnerability could result in unintended data leakage between match rounds, potentially leading to incorrect processing of netfilter rules.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.