Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's NFS server implementation can lead to undefined behavior when processing certain requests. Specifically, the function nfsd4_spo_must_allow() must verify that the request is a version 4 compound request. The vulnerability arises because, without this check, examining the request's state could produce unpredictable results.
Exploiting this vulnerability could cause undefined behavior in the NFS server, potentially leading to incorrect handling of requests or other unforeseen issues.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.