Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's ksmbd component has been identified, involving a dangling pointer in the Kerberos authentication process. The issue arises because the function 'krb_authenticate' frees the 'sess->user' pointer without resetting it to NULL. Subsequently, 'smb2_sess_setup' can access this freed memory, leading to potential undefined behavior. This vulnerability has been addressed in the Linux kernel.
Exploitation of this vulnerability could lead to access of freed memory, potentially causing undefined behavior or memory corruption.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.