Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A use-after-free vulnerability has been identified in the Linux kernel's net/mlx5 component. This issue arises during the matcher disconnect process when a firmware failure occurs. The current error handling approach attempts to reconnect the matcher and returns an error, which can lead to a freed matcher remaining on the matchers list. This situation creates a use-after-free condition, causing a crash. The vulnerability also has the potential to disrupt the steering state by incorrectly linking matchers, leading to resource leakage.
Exploitation of this vulnerability causes a use-after-free condition, resulting in a crash. However, it also disrupts the management of matchers, potentially causing incorrect connections between them, and leads to a leakage of system resources.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.