Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A use-after-free vulnerability has been identified in the Linux kernel's ksmbd component, specifically within the Kerberos authentication process. The issue arises because the session's user pointer is not properly managed, allowing another thread to access the user data after it has been freed, but before the pointer is reset to NULL. This creates a risk of unintended behavior or memory corruption.
Exploitation of this vulnerability could lead to memory corruption issues, potentially allowing for arbitrary code execution or causing a denial-of-service condition.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.