Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
- >= 6.17.0-rc7_for_upstream_min_debug_2025_10_02_12_44, < 6.18.0-rc4
A vulnerability in the Linux kernel's devlink rate management can lead to a reference count error. The issue arises because the function responsible for destroying rate nodes does not properly clear the parent pointer of rate objects, leaving a dangling reference. This problem has been observed in the netdevsim and mlx5 components of the kernel.
Exploitation of this vulnerability causes a reference count error, leading to memory management issues such as memory leaks.
The vulnerability can be reproduced by creating a new device through the netdevsim bus, adding a devlink port function rate, and then setting a parent node for that rate. After removing the device, the dangling pointer issue can be observed as a reference count error in the system logs. This reproduction process can be done manually or through a script that automates the steps.
Users should update to the latest version of the Linux kernel where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.