Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A double-free vulnerability has been identified in the Linux kernel's DRM XE NVM component. This issue arises during the initialization of auxiliary devices, where a failure in adding the device can trigger a release callback that frees memory. The vulnerability affects the Linux kernel stable tree, specifically in versions prior to the patch addressing this issue.
Exploitation of this vulnerability leads to a double-free condition, which can cause memory corruption and potentially allow for arbitrary code execution.
Users can apply the patch available in the Linux kernel stable repository to address this vulnerability. Instructions for downloading the patched version can be found in the Linux kernel documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.