Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
- >= 6.18, < 6.18.0-rc1
A vulnerability in the Linux kernel's namespace file system (nsfs) has been addressed by tightening permission checks for opening handles. Previously, even privileged services could access the namespaces of other privileged services, potentially leading to information leaks. The vulnerability has been fixed by implementing a centralized policy that restricts visibility between namespaces, ensuring that services cannot inadvertently share sensitive information. This issue affects Linux kernel versions 6.18 and later.
Exploitation of this vulnerability could allow for unauthorized access to namespace information, potentially leading to privilege escalation by enabling a service to access or interfere with the namespaces of other services.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.