Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's io_uring component has been addressed. The issue arose because the import of vectored registered buffers was incorrectly linked to the request 'req' instead of the appropriate notification io_kiocb, sr->notif. This misalignment is critical as the lifetimes of the two can differ. The vulnerability affected the Linux kernel stable tree.
The vulnerability could lead to improper handling of vectored buffer notifications, potentially causing issues in buffer management and data integrity during I/O operations.
Users can upgrade to the latest version of the Linux kernel stable tree to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.