Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
- >= 6.8, < 6.8.0-rc1
A vulnerability in the Linux kernel's IVPU driver could lead to use-after-free bugs by allowing recovery work to be scheduled even after device removal had begun. This issue has been addressed by changing the recovery work cancellation process to ensure no new recovery tasks can be queued once device removal starts. The vulnerability affects Linux kernel versions 6.8 and later.
The vulnerability could cause use-after-free bugs by allowing recovery processes to access resources that have already been freed, potentially leading to memory corruption or other unintended behavior.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.