Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A use-after-free vulnerability has been identified in the Linux kernel's ksmbd component. The issue arises in the 'ksmbd_free_work_struct' where an 'interim_entry' of 'ksmbd_work' could be deleted after an oplock is freed. This vulnerability allows for improper management of linked list entries, as the interim request could be sent immediately when an oplock break wait is required.
Exploitation of this vulnerability could lead to a use-after-free condition, potentially allowing for memory corruption or arbitrary code execution.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.