Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's handling of firmware data for OcteonTX2 boards has been addressed. The issue arose because the firmware was not properly checked before the kernel accessed shared data, particularly on boards without an active MAC block. This oversight could lead to kernel panics, as evidenced by an internal error message indicating a serious fault in the kernel's operation. The problem was traced to the OcteonTX2 AF driver, specifically in the RVU CGX and SDP components.
The vulnerability could cause a kernel panic, disrupting system operations and potentially leading to a denial of service.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. The specific commit addressing this issue is available in the Linux kernel stable tree.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.