Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A use-after-free vulnerability has been identified in the Linux kernel's SCPI (System Control and Power Interface) firmware handling. This issue arises because the SCPI information is not properly managed when the probing process fails. If the probe encounters an error, the SCPI information should remain null until a successful probe occurs. Failure to address this can lead to a use-after-free situation, as the SCPI operations could reference memory that was allocated but subsequently freed when the probe failed.
Exploitation of this vulnerability could lead to a use-after-free condition, potentially allowing for memory corruption or arbitrary code execution.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.