CVE-2023-51043 is a use-after-free flaw in the Linux kernel DRM atomic modesetting subsystem. A local low-privileged attacker can race a nonblocking atomic display commit against unloading or removing a graphics driver, allowing the asynchronous commit to outlive the drm_device reference inherited from its ioctl context. Successful exploitation can cause denial of service or potentially local privilege escalation; Red Hat assigns a CVSS v3.1 score of 7.0.
The issue affects kernels before version 6.4.5 and was fixed upstream in commit 4e076c73e4f6e90816b30fcd4a0d7ab365087255, which makes each drm_atomic_state retain a drm_device reference until the atomic state is freed. Red Hat identified affected RHEL 8 and 9, including selected Extended Update Support, real-time kernel, and Red Hat Virtualization releases, and issued kernel updates. Organizations should deploy the applicable kernel updates; where patching is not immediately possible, Red Hat recommends preventing the DRM kernel module from loading.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:2394, providing RHEL 9 kernel updates that address CVE-2023-51043.
Red Hat issued RHSA-2024:1404, providing a kernel update that fixes CVE-2023-51043 for RHEL 8.8 Extended Update Support.
Red Hat issued RHSA-2024:1188 with a fixed kernel for RHEL 8.6 Extended Update Support; the update also covered Red Hat Virtualization 4 for RHEL 8.
Red Hat issued RHSA-2024:1018 and RHSA-2024:1019, delivering kernel and kernel-rt fixes for RHEL 9.2 Extended Update Support.
Rohit Keshri reported the Red Hat bug record for CVE-2023-51043.
Red Hat issued RHSA-2023:7077, providing RHEL 8 kernel updates that fix CVE-2023-51043, a DRM atomic modesetting use-after-free vulnerability.
Linus Torvalds committed upstream Linux patch 4e076c73e4f6e90816b30fcd4a0d7ab365087255, which makes DRM atomic states retain a drm_device reference to prevent a nonblocking commit from outliving a graphics-driver unload or removal.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.