CVE-2023-33951
Last modified
CVE-2023-33951 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. The issue results from improper locking when performing operations on an object. This flaw allows a local privileged user to disclose information in the context of the kernel.
Metrics
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 6.3.9 |
| Redhat | Enterprise Linux | 8.0 |
| Redhat | Enterprise Linux | 9.0 |
| Redhat | Enterprise Linux For Real Time | 8.0 |
| Redhat | Enterprise Linux For Real Time For Nfv | 8.0 |
References
- https://access.redhat.com/errata/RHSA-2023:6583Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6901Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7077Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-33951Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2218195Issue Tracking, Patch
- https://www.zerodayinitiative.com/advisories/ZDI-CAN-20110/Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2023:6583Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6901Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7077Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-33951Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2218195Issue Tracking, Patch
- https://www.zerodayinitiative.com/advisories/ZDI-CAN-20110/Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-33951?
How severe is CVE-2023-33951?
How do I fix CVE-2023-33951?
Are you affected by CVE-2023-33951?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
