Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability exists in the Linux kernel's SPI QPIC SNAND driver, where the on-host hardware ECC engine remains registered during error conditions and device removal. This oversight can lead to use-after-free issues. The vulnerability has been addressed by modifying the probe function to properly unregister the ECC engine on errors and adding the missing unregistration call during device removal.
The vulnerability could cause use-after-free issues, potentially leading to memory corruption or exploitation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.