Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A use-after-free vulnerability has been identified in the Linux kernel's mt76 wireless driver. This issue arises during the removal of a station, where a race condition allows a transmission (tx) status skb (socket buffer) to be added to the status tracking IDR (Index Descriptor Register) after it has already been cleaned up. As a result, the wcid (wireless context identifier) remains linked in the status poll list, potentially leading to memory corruption. The vulnerability can be exploited by manipulating ongoing transmission activities to interfere with the status tracking process.
Exploitation of this vulnerability can cause a use-after-free condition, leading to memory corruption.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.