Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
- >= 6.14, < 6.14.0-rc1
A use-after-free vulnerability has been identified in the Linux kernel's memory accounting cgroup feature. This issue arises from the improper management of memory pools, which can lead to a use-after-free condition. The vulnerability was introduced in version 6.14 and exists in the 'dmem' memory accounting cgroup. The problem occurs because a memory pool can still be referenced by a caller after its associated memory region has been unregistered, allowing for potential exploitation.
Exploitation of this vulnerability can lead to a use-after-free condition, causing a slab memory corruption issue. This type of vulnerability can often be exploited to execute arbitrary code or cause a denial-of-service condition by crashing the system.
Users can upgrade to the latest stable version of the Linux kernel to address this vulnerability. The patch for this issue is included in the official Linux kernel repository.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.