Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's IOAM6 net component can lead to out-of-bounds access in the transmission queue array. This issue arises when a packet is on the reception path, and the queue mapping exceeds the number of available transmission queues, potentially causing memory corruption. The vulnerability has been addressed by adding a check to prevent the index from exceeding the allowed range. Additionally, a missing lock around queue statistics has been added to ensure proper synchronization.
Exploitation of this vulnerability can lead to out-of-bounds memory access, which may cause memory corruption or undefined behavior in the kernel.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched version are available on the official Linux kernel website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.