Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
- >= 5.15.0, < 5.15.0-121-generic
A vulnerability in the Linux kernel's Open vSwitch component has been fixed, addressing an infinite loop issue in MPLS packet parsing. The problem arose when MPLS packets did not conclude with the bottom label stack, leading to a deadlock scenario. This occurred because the label count value had wrapped around, causing a soft lockup where the CPU became unresponsive. The issue was identified as an array index out-of-bounds error, with the stack backtrace indicating the loop's origin in the Open vSwitch flow handling.
Exploitation of this vulnerability caused a soft lockup, where the CPU became stuck and unresponsive, disrupting normal system operations.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.