CVE-2024-41012 is a use-after-free vulnerability in Linux kernel POSIX file-lock handling. When fcntl_setlk() races with close(), cleanup attempts to remove the newly created lock through do_lock_file_wait(). A Linux Security Module can permit lock creation but deny removal. Removal through posix_lock_file() can also fail because of a GFP_KERNEL allocation failure while splitting a lock range. These failures can leave a stale lock that causes use-after-free reads in lock_get_status() when userspace reads the procfs lock listing. The flaw likely permits arbitrary kernel-memory disclosure but cannot corrupt kernel memory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel file-locking vulnerability caused by a race between fcntl_setlk() and close(). Security-module restrictions or allocation failures can prevent removal of a lock, leading to use-after-free reads through /proc/locks and potentially arbitrary kernel-memory disclosure. The advisory rates it Medium, with a CVSS v3 base score of 6.3. The fix uses locks_remove_posix() to reliably remove the locks; affected Google COS kernel packages should be updated to version 18613.0.3 or later.
A locally exploitable vulnerability affecting Unity Linux systems, rated CVSS v3 5.5 (AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H) in the referenced security check.
A Linux kernel file-locking flaw involving a race condition between fcntl and close operations that could prevent locks from being removed reliably.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.