CVE-2023-51043: Use After Free
In the Linux kernel before 6.4.5 drivers/gpu/drm/drmatomic.c has a use-after-free during a race condition between a nonblocking atomic commit and a driver unload.
Other sources
In the Linux kernel before 6.4.5, drivers/gpu/drm/drmatomic.c has a use-after-free during a race condition between a nonblocking atomic commit and a driver unload.
— Launchpad
Linux Kernel could allow a local authenticated attacker to gain elevated privileges on the system, caused by a use-after-free due to a race condition between a nonblocking atomic commit and a driver unload in drivers/gpu/drm/drmatomic.c. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
redhat/Kernelto a version that resolves this vulnerability.Fixed in 6.5 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 6.4.5
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51043?
CVE-2023-51043 is classified as a high severity vulnerability due to its use-after-free condition that can be exploited during a race condition.
How do I fix CVE-2023-51043?
To fix CVE-2023-51043, update your Linux kernel to version 6.4.5 or later.
What types of systems are affected by CVE-2023-51043?
CVE-2023-51043 affects various Linux kernel versions prior to 6.4.5, impacting systems using the kernel for GPU operations.
What is the risk of exploitation for CVE-2023-51043?
The risk of exploitation for CVE-2023-51043 includes potential denial of service or system instability due to unhandled race conditions.
Which Linux distributions are vulnerable to CVE-2023-51043?
Popular Linux distributions like Debian and Red Hat with versions below 6.4.5 are vulnerable to CVE-2023-51043.