CVE-2023-51042: High Fixes in Linux KernelHigh Fixes CVE-2023-6931 in Linux KernelHigh Fixes CVE-2023-6817 in Linux KernelHigh Fixes CVE-2023-46813 in Linux KernelHigh Fixes CVE-2023-6932 in Linux Kernel
In the Linux kernel before 6.4.12 amdgpucswaitallfences in drivers/gpu/drm/amd/amdgpu/amdgpucs.c has a fence use-after-free.
Other sources
In the Linux kernel before 6.4.12, amdgpucswaitallfences in drivers/gpu/drm/amd/amdgpu/amdgpucs.c has a fence use-after-free.
— MITRE
Linux Kernel could allow a local authenticated attacker to gain elevated privileges on the system, caused by a fence use-after-free flaw in the amdgpucswaitallfences function in drivers/gpu/drm/amd/amdgpu/amdgpucs.c. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges.
— IBM
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-51042?
CVE-2023-51042 is classified as a high severity vulnerability due to its potential to cause a use-after-free condition in the Linux kernel.
How do I fix CVE-2023-51042?
To fix CVE-2023-51042, upgrade your Linux kernel to version 6.4.12 or later, or apply the appropriate patch provided by your distribution.
What systems are affected by CVE-2023-51042?
CVE-2023-51042 affects the Linux kernel versions prior to 6.4.12 and especially impacts IBM QRadar SIEM versions up to 7.5.0 UP8 IF01.
What components are involved in CVE-2023-51042?
CVE-2023-51042 involves the amdgpu_cs_wait_all_fences function located in the amdgpu driver within the Linux kernel.
Is a workaround available for CVE-2023-51042?
Currently, there are no known workarounds for CVE-2023-51042, so immediate remediation through updates is recommended.