CVE-2024-38581: drm/amdgpu/mes: fix use-after-free issue
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/mes: fix use-after-free issue
Delete fence fallback timer to fix the ramdom use-after-free issue.
v2: move to amdgpumes.c
Other sources
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/mes: fix use-after-free issue
The Linux kernel CVE team has assigned CVE-2024-38581 to this issue.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024061948-CVE-2024-38581-592d@gregkh/T
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.1.93 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.6.33 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.8.12 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.9
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38581?
CVE-2024-38581 is rated as a high severity vulnerability due to potential exploitability in the Linux kernel.
How do I fix CVE-2024-38581?
To fix CVE-2024-38581, update your Linux kernel to version 6.1.93 or later, or to 6.6.33, 6.8.12, or 6.9.
Which Linux distributions are affected by CVE-2024-38581?
CVE-2024-38581 affects various distributions that use vulnerable versions of the Linux kernel including Red Hat-based systems.
What components of the Linux kernel are impacted by CVE-2024-38581?
CVE-2024-38581 impacts the Direct Rendering Manager (DRM) component related to the AMDGPU driver.
Is there a workaround for CVE-2024-38581?
There is no official workaround for CVE-2024-38581; the recommended action is to apply the necessary kernel updates.