A use-after-free vulnerability in the Linux kernel Consumer Electronics Control (CEC) subsystem, tracked as CVE-2024-23848, can occur in cec_queue_msg_fh through a race condition in the CEC ioctl path. Kernel fuzzing showed one thread could continue accessing a struct cec_fh message queue after another thread freed the object, producing a reproducible KASAN slab-use-after-free crash. Related testing also exposed a task hang, warnings, and a general-protection fault, with several issues suspected to share a locking-related cause.
Red Hat rated CVE-2024-23848 as moderate severity with a CVSS 3.1 score of 6.7, citing potential confidentiality, integrity, and availability effects; NVD and CVE.org assigned 5.5, primarily for availability impact. Fixes were released for standard and real-time kernels in RHEL 8 and for the standard RHEL 9 kernel, including RHEL 9.4 Extended Update Support. RHEL 6, RHEL 7, and RHEL 7 kernel-rt are unaffected, while the RHEL 9 real-time kernel is listed as will not fix.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat fixed the CVE-2024-23848 use-after-free vulnerability in the RHEL 8 standard kernel through RHSA-2024:7000 and in the RHEL 8 real-time kernel through RHSA-2024:7001.
Red Hat released RHSA-2025:3510 to fix CVE-2024-23848 in the Red Hat Enterprise Linux 9.4 Extended Update Support kernel.
Red Hat released RHSA-2024:9315 to fix CVE-2024-23848 in the Red Hat Enterprise Linux 9 kernel.
Linux media maintainer Hans Verkuil said he had identified two issues, was investigating a third, and intended to submit patches for retesting. He assessed that several of the reported CEC crashes could share a locking-related root cause.
Researchers Chenyuan Yang, Zijie Zhao, and colleagues reported five crashes found by fuzzing the Linux kernel CEC device ioctl path, including a reproducible KASAN slab-use-after-free in cec_queue_msg_fh. They supplied a Syzkaller reproducer showing a race in which a struct cec_fh can be used after it is freed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.