Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's batman-adv module can lead to a denial-of-service condition. When the unacked_list is unbound, an attacker can send messages with small lengths and specific sequence numbers, creating gaps that force the receiver to allocate more unacked_list entries. This can cause an out-of-memory situation or increase management overhead, wasting CPU cycles on list searches. The vulnerability affects the Linux kernel stable tree.
Exploitation of this vulnerability can cause an out-of-memory situation or increase CPU overhead due to excessive list management, potentially leading to a denial-of-service condition.
To reproduce this vulnerability, send messages with small lengths and carefully chosen sequence numbers that create gaps. This will force the receiver to allocate additional unacked_list entries, potentially leading to an out-of-memory situation or increased CPU usage from managing a large list.
The vulnerability has been addressed in the Linux kernel. Users should upgrade to the latest version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.