CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's handling of driver attachment, specifically in the hv:vmbus driver, where the match() callback is executed without proper device locking. This oversight can lead to a use-after-free (UAF) condition, potentially allowing an attacker to exploit the system. Organizations running Linux environments, particularly those utilizing the hv:vmbus driver, should prioritize patching this vulnerability to mitigate the risk of exploitation.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: use generic driver_override infrastructure When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF. Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally. Note that calling match() from __driver_attach() without the device lock held is intentional. [1]