Linux kernel
cpe:2.3:o:kernel:linux_kernel:*:*:*:*:*:*:*
A use-after-free vulnerability has been addressed in the Linux kernel's XFS file system, specifically within the extended attribute repair process. The issue arose because the function responsible for setting up the value buffer could allocate a new buffer, leaving any prior references as dangling pointers. This vulnerability affects the Linux kernel stable group.
The vulnerability could lead to a use-after-free condition, potentially allowing for arbitrary code execution or memory corruption.
The vulnerability can be reproduced by invoking the XFS extended attribute repair function in a scenario where the value buffer is allocated. This will create a dangling pointer reference, leading to a use-after-free condition.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.