CVE-2022-41218 is a medium-severity use-after-free flaw in the Linux kernel's dvb-core subsystem, affecting Digital Video Broadcasting devices. A local low-privileged attacker could race malicious code against removal of a USB DVB demultiplexer or similar device, causing freed memory in drivers/media/dvb-core/dmxdev.c to be accessed. Successful exploitation could crash the host or potentially elevate privileges, although Red Hat rated the issue CVSS 5.5 because physical device removal and a difficult-to-win race condition are required.
Kernel developers identified related DVB frontend, network, and device-registration races involving concurrent open, close, and USB-disconnect operations; KASAN reproduced the use-after-free conditions on Linux 6.1.0-rc2 and later. Fedora shipped a fix in kernel 6.0.18 stable updates, while Red Hat remediated affected RHEL 8 kernel and kernel-rt packages through RHSA-2023:2736 and RHSA-2023:2951, with subsequent coverage for RHEL 8.6 EUS and Red Hat Virtualization 4. Organizations unable to patch can mitigate exposure by preventing the dvb-core module from loading; RHEL 9 kernel-rt was marked will not fix.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat fixed affected RHEL 8 kernel-rt packages through RHSA-2023:2736 and RHEL 8 kernel packages through RHSA-2023:2951. Red Hat also closed its tracking bug for the vulnerability.
Hyunwoo Kim submitted a four-patch Linux kernel series to fix multiple race-condition use-after-free issues in DVB core components and a memory leak in the ttusb-dec USB driver. The author said most patches resembled an earlier security patch for CVE-2022-41218.
CVE-2022-41218 was published as a moderate use-after-free vulnerability in the Linux kernel dvb-core subsystem, with potential for system crashes or local privilege escalation.
A patch addressing the issue was referenced in a Linux kernel mailing-list post.
A use-after-free race condition affecting the Linux kernel's DVB core demultiplexer handling was reported. Exploitation requires local malicious code execution alongside physical removal of a USB DVB device.
RHSA-2024:0412 fixed the vulnerability for the RHEL 8.6 Extended Update Support kernel and Red Hat Virtualization 4 on RHEL 8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.