cbcvebase.
CVE-2024-41093
published 2024-07-29

CVE-2024-41093: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: avoid using null object of framebuffer Instead of using state->fb->obj[0]…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.2th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: avoid using null object of framebuffer Instead of using state->fb->obj[0] directly, get object from framebuffer by calling drm_gem_fb_get_obj() and return error code when object is null to avoid using null object of framebuffer.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
debianlinux-6.1< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
linuxlinux
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < 7f35e01cb0ea4d295f5c067bb5c67dfcddaf05bc7f35e01cb0ea4d295f5c067bb5c67dfcddaf05bc
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < 6ce0544cabaa608018d5922ab404dc656a9d84476ce0544cabaa608018d5922ab404dc656a9d8447
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < 330c8c1453848c04d335bad81371a66710210800330c8c1453848c04d335bad81371a66710210800
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < dd9ec0ea4cdde0fc48116e63969fc83e81d7ef46dd9ec0ea4cdde0fc48116e63969fc83e81d7ef46
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < bcfa48ff785bd121316592b131ff6531e3e696bbbcfa48ff785bd121316592b131ff6531e3e696bb
linuxlinux_kernel< 5.15.1625.15.162
linuxlinux_kernel>= 0 < 6.1.98-16.1.98-1
linuxlinux_kernel>= 0 < 6.9.8-16.9.8-1
linuxlinux_kernel>= 0 < 6.9.8-16.9.8-1
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 5.16 < 6.1.976.1.97
linuxlinux_kernel>= 6.2 < 6.6.376.6.37
linuxlinux_kernel>= 6.7 < 6.9.86.9.8
msrcazl3_kernel_6.6.35.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.43.1-7_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.