CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's eventfs subsystem, specifically in the eventfs_remove_rec() function, which can lead to a use-after-free condition. This flaw could allow an attacker to exploit the race condition, potentially leading to arbitrary code execution or system instability. Organizations using Linux-based systems, especially those relying on eventfs for event management, should prioritize patching this vulnerability to mitigate the associated risks.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: eventfs: Fix use-after-free in eventfs_remove_rec() eventfs_remove_rec() recursively removes the child at the current loop position. After the recursive call returns, list_for_each_entry() advances by reading list.next from the removed child. If free_ei() drops the final reference, release_ei() reuses the list/rcu union to queue an SRCU callback. The child may be freed before that read. The eventfs_mutex serializes list updates, but it does not keep the removed child alive or prevent the SRCU callback from running. Use list_for_each_entry_safe() to save the next sibling before recursively removing the current child.