CVE-2024-23848: Use After Free
In the Linux kernel through 6.7.1, there is a use-after-free in cecqueuemsgfh, related to drivers/media/cec/core/cec-adap.c and drivers/media/cec/core/cec-api.c.
Other sources
Linux Kernel is vulnerable to a denial of service, caused by a use-after-free in cecqueuemsgfh. A local attacker could exploit this vulnerability to cause the system to crash.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23848?
CVE-2024-23848 is considered a critical vulnerability due to its use-after-free nature that can lead to potential arbitrary code execution.
How do I fix CVE-2024-23848?
To remediate CVE-2024-23848, update your Linux kernel to version 6.7.2 or later.
Which versions of the Linux kernel are affected by CVE-2024-23848?
CVE-2024-23848 affects all Linux kernel versions up to and including 6.7.1.
What components are primarily impacted by CVE-2024-23848?
CVE-2024-23848 impacts the cec_queue_msg_fh function within the media/cec core files in the Linux kernel.
Is there a patch available for CVE-2024-23848?
Yes, patches have been released for CVE-2024-23848 in the subsequent kernel updates after version 6.7.1.