Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A use-after-free vulnerability has been identified in the Linux kernel's RDMA (Remote Direct Memory Access) subsystem. This issue arises when renaming device names, leading to a slab-use-after-free condition. The vulnerability was reported by Syzbot and is present in version 6.14.0-rc4.
Exploitation of this vulnerability can lead to a use-after-free condition, potentially allowing for arbitrary code execution or memory corruption.
The vulnerability can be reproduced by registering an RDMA device and then renaming it, which triggers the use-after-free condition. This can be done using a tool like Syzkaller, which automates the process of finding and exploiting vulnerabilities in the Linux kernel.
Users can upgrade to the latest stable version of the Linux kernel where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.