Description
NeKernal is a free and open-source operating system stack. Prior to version 0.0.3, there are several memory safety issues that can lead to memory corruption, disk image corruption, denial of service, and potential code execution. These issues stem from unchecked memory operations, unsafe typecasting, and improper input validation. This issue has been patched in version 0.0.3.
Problem types
CWE-20: Improper Input Validation
CWE-770: Allocation of Resources Without Limits or Throttling
Product status
References
github.com/...kernel/security/advisories/GHSA-cmp2-5f6g-mw34
github.com/nekernel-org/nekernel/pull/35
github.com/nekernel-org/nekernel/pull/36
github.com/...ommit/6506875ad0ab210b82a5c4ce227bf851508de17d
github.com/...ommit/6511afbf405c31513bc88ab06bca58218610a994