Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's Rxrpc implementation has been addressed. The issue arose because the DATA and RESPONSE packet handlers did not properly unshare packets containing externally-owned paged fragments before processing them. This oversight allowed such packets to bypass necessary security operations, leading to potential vulnerabilities. The problem has been fixed by extending the packet handling to unshare these fragments, ensuring proper security measures are applied.
Exploitation of this vulnerability could lead to improper handling of packet decryption, potentially allowing for security operations to be bypassed.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.