Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A use-after-free vulnerability has been identified in the Linux kernel's handling of Rose timers. This issue arises because the timers only acquire the socket spinlock without verifying if the socket is owned by a user thread. The vulnerability can lead to a slab-use-after-free condition, allowing for potential memory corruption.
Exploitation of this vulnerability causes a use-after-free condition in the Rose timer management, leading to memory corruption.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.