Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's krb5enc cryptographic implementation allows asynchronous decryption to skip crucial hash verification, potentially compromising data integrity. This issue arises because the decryption process incorrectly signals completion before the integrity check is performed, unlike the encryption process, which properly sequences callbacks to ensure verification. The vulnerability affects the stable versions of the Linux kernel.
Exploitation of this vulnerability leads to the omission of integrity checks during asynchronous decryption, allowing for potential manipulation or corruption of data without detection.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.