Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's virtio-net implementation can lead to information leakage during GSO tunnel negotiations. The issue arises because the function 'virtio_net_hdr_tnl_from_skb()' fails to zero out unused hash fields, potentially allowing residual data to be exposed to the other side. This vulnerability affects the Linux kernel stable tree.
The vulnerability could result in unintended information disclosure between network peers.
Users can upgrade to the latest version of the Linux kernel stable tree to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.