Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A use-after-free vulnerability has been identified in the Linux kernel's SCSI LPFC driver. This issue arises in the 'dev_loss_tmo_callbk' function, where a node list reference can be improperly accessed after it has been freed. The vulnerability may occur during driver unloading or when managing fatal errors. The problem has been addressed by reorganizing the code to prevent the use-after-free condition, ensuring that node list references are properly managed.
Exploitation of this vulnerability could lead to a use-after-free condition, potentially allowing for memory corruption or arbitrary code execution.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.