Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's virtio-net component can lead to an out-of-bounds read. This issue arises in the xdp_linearize_page function, where the length of received data is not properly checked against the allocated buffer size. The oversight can cause unauthorized memory access. The vulnerability has been addressed by implementing the necessary length verification.
Exploitation of this vulnerability can result in an out-of-bounds read, potentially leading to information disclosure or memory corruption.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.