Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A use-after-free vulnerability has been identified in the Linux kernel's workqueue implementation. This issue arises when the rescuer is detached from the pool, leading to a premature release of a reference, which can be exploited. The vulnerability was introduced by a commit that reaped normal workers but failed to properly manage the rescuer, removing the necessary synchronization that prevented the use-after-free condition.
Exploitation of this vulnerability leads to a use-after-free condition, which can commonly result in arbitrary code execution or memory corruption.
The vulnerability has been addressed in the Linux kernel. Users should upgrade to the latest version where this issue has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.