Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A memory corruption vulnerability has been identified in the Linux kernel's IOMMU S390 implementation, specifically when using the identity domain. The issue arises because the identity domain is not associated with a valid S390 domain, leading to a global-out-of-bounds error. This vulnerability was discovered using KASAN, which reported the memory access issue when a device was managed through the identity domain.
Exploitation of this vulnerability causes memory corruption, with the potential for leading to arbitrary code execution or other memory-related vulnerabilities.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for downloading the patched version are available on the official Linux kernel website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.