A race condition in the Linux kernel's r592 MemoryStick host-controller driver can trigger a use-after-free during device or module removal. The r592_remove routine could free the host object while the detect timer was still able to queue work referencing it, enabling a local attacker with specialized peripheral hardware, high privileges, and precise timing to crash the system or potentially expose kernel information. The issue is tracked as CVE-2023-35825 and CVE-2023-3141, with Red Hat assigning a CVSS v3.1 score of 6.4.
The upstream fix stops and synchronizes the detect timer with del_timer_sync(&dev->detect_timer) before device cleanup, preventing active timer callbacks from accessing freed memory. Red Hat released corrected kernel packages for multiple RHEL 8 and RHEL 9 streams and Red Hat Virtualization 4; RHEL 9 kernel-rt remained affected in the referenced advisories, while RHEL 6 and 7 packages were outside support scope. Organizations using affected systems should apply the applicable Red Hat kernel updates, particularly where r592 hardware is present or can be physically attached.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2023:6901 for RHEL 8 kernel-rt and RHSA-2023:7077 for the RHEL 8 kernel, addressing the r592 use-after-free vulnerability.
Red Hat released RHSA-2023:6583, fixing the r592 use-after-free issue tracked as CVE-2023-35825 and CVE-2023-3141 in the RHEL 9 kernel.
Red Hat published CVE-2023-35825 for the r592 device-driver race condition, which can lead to a use-after-free and system crash or other undefined behavior.
Zheng Wang submitted a Linux kernel patch to fix a use-after-free race in the r592 MemoryStick host-controller driver's r592_remove cleanup path. The patch synchronizes and stops the detect timer before device cleanup.
Red Hat released RHSA-2024:0724, fixing the r592 vulnerability in the RHEL 8.6 Extended Update Support kernel and Red Hat Virtualization 4 for RHEL 8.
Red Hat released RHSA-2024:0575 to fix the r592 vulnerability in the RHEL 8.8 Extended Update Support kernel.
Ulf Hansson accepted the r592 driver patch for the Linux kernel's next branch.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.