Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A use-after-free vulnerability has been identified in the Linux kernel's PDS core component. This vulnerability allows for a write-after-free condition, which was revealed during stress testing. The issue arises in the 'pdsc_auxbus_dev_del' function, where a client ID is improperly cleared, leading to potential memory corruption. The vulnerability is related to the order of thread execution, as the actual device uninitialization may occur on a separate thread after the problematic code has run.
Exploitation of this vulnerability could lead to memory corruption, allowing for a use-after-free condition that could be exploited to write to freed memory, potentially causing arbitrary code execution or other unintended behavior.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.