Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's sysfs directory management can lead to unintended consequences when updating named groups. If the file creation process fails, the system erroneously removes the associated directory, disrupting the sysfs group that was not user-created. This issue affects the Linux kernel stable tree.
The vulnerability can cause the unintentional deletion of sysfs groups, disrupting system functionality and potentially leading to broader system issues.
To reproduce this vulnerability, create a named sysfs group and then simulate a failure in the file creation process, such as running out of memory. During the update, the kernel will remove the group directory, causing the group to be lost.
The vulnerability has been addressed in the Linux kernel. Users should upgrade to the latest version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.