Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's io_uring implementation has been addressed. The issue involved improper handling of chained notification contexts, which could lead to ambiguous reports and assumptions about notification completion. The vulnerability has been resolved by ensuring that zero-copy (zc) operations only link buffer information for requests originating from the same context.
Exploitation of this vulnerability could lead to incorrect assumptions about the completion of notifications in the io_uring subsystem, potentially causing synchronization issues or mismanagement of resources.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.