Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A use-after-free vulnerability has been identified in the Linux kernel's BFQ IO scheduler. This issue arises when BIOS queued into the BFQ scheduler are linked to a cgroup that has already been offlined. As a result, the associated BFQ group can be prematurely freed once the last BIO is processed, leading to potential exploitation by users of the service tree. The vulnerability affects several versions of the Linux kernel.
Exploitation of this vulnerability can lead to use-after-free conditions, potentially allowing for arbitrary code execution or memory corruption.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.