Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A refcount leak vulnerability has been identified in the Linux kernel's USB host controller driver, specifically within the EHCI (Enhanced Host Controller Interface) implementation for PowerPC platforms. The issue arises in the 'ehci_hcd_ppc_of_probeof_find_compatible_node' function, where a node pointer is returned with an incremented reference count. The function fails to properly decrement the reference count before returning, leading to a memory management issue. The vulnerability has been addressed by adding the missing 'of_node_put()' call to prevent the refcount leak.
Exploitation of this vulnerability could lead to a refcount leak, causing memory management issues that may be exploited for arbitrary code execution or denial-of-service conditions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.