CVE-2024-41093 is a null-pointer dereference in the Linux kernel's AMDGPU DRM virtual KMS code. A local low-privileged user could trigger a kernel crash and denial of service because the driver accessed state->fb->obj[0] without confirming that the framebuffer object existed. The issue is rated Moderate by Red Hat, with a CVSS v3.1 score of 5.5 and high availability impact.
The upstream fix replaces the direct object access with drm_gem_fb_get_obj() and returns an error when no framebuffer object is present. Corrected upstream kernels include 5.15.162, 6.1.97, 6.6.37, 6.9.8, and 6.10; Red Hat has released updated RHEL 8 and RHEL 9 kernel and kernel-rt packages, while RHEL 6 and 7 are not affected. Organizations using AMDGPU should deploy the relevant kernel updates and reboot affected hosts.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:8856 for the RHEL 8 kernel and RHSA-2024:8870 for the RHEL 8 kernel-rt, addressing CVE-2024-41093.
Red Hat released RHSA-2024:6993, fixing CVE-2024-41093 in the Red Hat Enterprise Linux 8.8 Extended Update Support kernel.
Red Hat released RHSA-2024:10771, RHSA-2024:10772, and RHSA-2024:10773, fixing CVE-2024-41093 in RHEL 9.4 EUS kernel and RHEL 9.2 EUS kernel and kernel-rt packages.
Red Hat released RHSA-2024:9315 to fix CVE-2024-41093 in the Red Hat Enterprise Linux 9 kernel.
Fixes for the AMDGPU DRM flaw were included in Linux kernel versions 5.15.162, 6.1.97, 6.6.37, 6.9.8, and 6.10. The Linux kernel CVE team recommended upgrading to the latest stable release rather than cherry-picking an individual patch.
The Linux kernel CVE team assigned CVE-2024-41093 for a NULL framebuffer-object dereference in AMDGPU virtual KMS code. The affected code accessed state->fb->obj[0] directly; the fix obtains the object through drm_gem_fb_get_obj() and returns an error if it is NULL.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.