Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A use-after-free vulnerability has been identified in the Linux kernel's DRBD component. The issue arises in the 'get_initial_state' function, where a socket buffer (skb) is freed but then improperly accessed, leading to potential memory corruption. This vulnerability can be exploited because the same skb can be freed in related notification functions, creating additional use-after-free scenarios.
Exploitation of this vulnerability leads to a use-after-free condition, which can commonly be exploited to execute arbitrary code or cause a denial-of-service by crashing the system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.