Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability has been identified in the Linux kernel's statmount_string function, where an output offset pointer ('offp') can remain uninitialized. This issue arises because certain cases directly assign values to struct fields without using the designated offset pointer, leading to a potential uninitialized dereference when the pointer is later updated. The vulnerability affects the Linux kernel stable tree.
The vulnerability could lead to a situation where an uninitialized pointer is dereferenced, potentially causing undefined behavior or a crash.
Users can upgrade to the latest version of the Linux kernel stable tree to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.