Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +3 more
- >= 6.19.0-rc8, < 6.19.0-rc8-yocto-standard
A NULL pointer dereference vulnerability has been identified in the Linux kernel's Stratix 10 Remote System Update (RSU) driver. This issue occurs when RSU is disabled in the First Stage Boot Loader (FSBL). The driver attempts to execute a thread that accesses a freed channel, leading to a kernel panic. The vulnerability arises because the driver fails to properly handle the absence of RSU, allowing a thread to be registered with an invalid channel, which then causes the NULL pointer dereference.
Exploitation of this vulnerability leads to a kernel panic due to a NULL pointer dereference, causing a denial of service by crashing the kernel.
Users can apply the available patch in the Linux kernel stable tree to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.