Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
- >= 6.18.0-rc4, < 6.18.0-rc4-virtme-g36b21a067510
A use-after-free vulnerability has been identified in the Linux kernel's mlxsw spectrum router component. This issue arises when the driver dereferences a neighbour pointer without holding a proper reference, leading to a potential memory access error. The vulnerability was reproduced several times, indicating a reliability issue that could be exploited under certain conditions.
Exploitation of this vulnerability causes a use-after-free condition, which can lead to memory corruption and potentially allow for arbitrary code execution.
The vulnerability can be reproduced by running a specific test over 300 times, which consistently triggers the use-after-free issue. This test can be integrated into a script or a testing framework that simulates the conditions under which the vulnerability occurs.
Users can apply the patch available in the Linux kernel stable tree to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.