Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's Direct Rendering Manager (DRM) subsystem, specifically within the XE virtual memory management, has been addressed. The issue arose because the function 'xe_svm_init()' was called too late in the virtual machine (VM) creation process. This delay allowed 'xe_svm_fini()' to be invoked prematurely on the error path, before the SVM state was properly initialized. The consequence was a series of error messages followed by a critical null pointer dereference.
Exploiting this vulnerability could lead to a fatal null pointer dereference, causing a crash or undefined behavior in the system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.