Impact
The vulnerability is a use‑after‑free flaw in ESET's Linux security products, identified as CWE‑416. Exploiting it can cause the kernel to crash, resulting in a system-wide panic and interruption of services. The impact is limited to denial of service; there is no evidence of data loss or remote code execution. The flaw allows the attacker to trigger a kernel panic directly through the affected product code.
Affected Systems
The flaw affects ESET Endpoint Antivirus for Linux and ESET Server Security for Linux. No specific version information is provided in the advisory; patching is recommended for all affected deployments.
Risk and Exploitability
The CVSS score of 6.7 places the vulnerability in the Moderate severity range, and the EPSS score of less than 1% indicates a low exploitation probability as of this analysis. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported. The attack vector is not explicitly described, so it is inferred that an attacker could trigger the flaw via malicious input to the ESET product, potentially requiring local or privileged access. Overall, the risk is moderate but mitigable through patching.
OpenCVE Enrichment