Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A use-after-free vulnerability has been identified in the Linux kernel's CXL (Compute Express Link) port management. This issue arises in versions of the kernel that include KASAN (Kernel Address Sanitizer) and DEBUG_KOBJECT_RELEASE, where a decoder release function may prematurely free a port reference. The vulnerability allows a read operation of size 8 from an invalid memory address, potentially leading to memory corruption or unauthorized access to sensitive data.
Exploitation of this vulnerability can lead to a use-after-free condition, allowing for memory corruption, which could be exploited to execute arbitrary code or cause a denial-of-service by crashing the system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.