Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A use-after-free vulnerability has been identified in the Linux kernel's HID Nvidia Shield driver. This issue arises from the improper management of the input device name, which is allocated using a deferred management function. When the input device is unregistered, the associated resources, including the name, are cleaned up and freed. However, the freed name is then used in a uevent, leading to a use-after-free condition. The vulnerability affects several versions of the Linux kernel.
Exploitation of this vulnerability could lead to a use-after-free condition, potentially allowing for memory corruption or arbitrary code execution.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for downloading the patched version are available on the Linux Kernel Archives.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.