Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
- >= 6.2, < 6.2.0-rc1
A vulnerability has been identified in the Linux kernel's IPMI driver, specifically in versions through 6.2. This issue arises from a bug introduced by a recent patch, which can cause the driver to enter an infinite loop if the Baseboard Management Controller (BMC) behaves improperly. Reports indicate that certain BMCs do exhibit this problematic behavior.
Exploitation of this vulnerability can lead to the IPMI driver getting stuck in an infinite loop, potentially causing a denial of service by preventing normal operations.
The vulnerability can be reproduced by applying the affected patch to the IPMI driver and then interacting with a BMC that exhibits the misbehavior described. This will cause the driver to enter an infinite loop, demonstrating the flaw introduced by the patch.
Users can revert the problematic patch to address this vulnerability. The patch can be downloaded from the Linux kernel stable tree.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.