Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's handling of IOMMU translation for MSI message addresses can lead to a use-after-free condition. This issue arises because the process of storing and using IOVA addresses for MSI interrupts is not properly synchronized, allowing potential races that can be exploited. The vulnerability is present in the kernel's interrupt handling when using the iommufd interface, which permits changes to the IOMMU domain during VFIO operations, creating a window for exploitation.
Exploitation of this vulnerability can lead to a use-after-free condition, potentially allowing for arbitrary memory access or manipulation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.