Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A refcount leak vulnerability has been identified in the PowerPC XIVE component of the Linux kernel. The issue arises in the function 'xive_spapr_initof_find_compatible_node()', which returns a node pointer with an incremented reference count. The vulnerability occurs because the function fails to properly decrement the reference count before returning, leading to a memory management issue.
Exploitation of this vulnerability could result in a refcount leak, causing improper memory management that may be exploited in certain scenarios.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.