First published: Tue Jan 23 2024(Updated: )
In the Linux kernel through 6.7.1, there is a use-after-free in cec_queue_msg_fh, related to drivers/media/cec/core/cec-adap.c and drivers/media/cec/core/cec-api.c.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | <=6.7.1 | |
IBM Security Verify Governance - Identity Manager | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager Software Stack | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager Virtual Appliance | <=ISVG 10.0.2 | |
IBM Security Verify Governance Identity Manager Container | <=ISVG 10.0.2 | |
debian/linux | 5.10.223-1 5.10.234-1 6.1.129-1 6.1.128-1 6.12.21-1 6.12.22-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23848 is considered a critical vulnerability due to its use-after-free nature that can lead to potential arbitrary code execution.
To remediate CVE-2024-23848, update your Linux kernel to version 6.7.2 or later.
CVE-2024-23848 affects all Linux kernel versions up to and including 6.7.1.
CVE-2024-23848 impacts the cec_queue_msg_fh function within the media/cec core files in the Linux kernel.
Yes, patches have been released for CVE-2024-23848 in the subsequent kernel updates after version 6.7.1.