VulnerabilityModified
CVE-2023-33951
A race condition vulnerability was found in the vmwgfx driver in the Linux kernel.
MEDIUM 5.3EPSS 0.34%
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. The issue results from improper locking when performing operations on an object. This flaw allows a local privileged user to disclose information in the context of the kernel.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 0.34% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-413, CWE-362, CWE-667
- Affected
- linux/linux kernel · redhat/enterprise linux · redhat/enterprise linux for real time · redhat/enterprise linux for real time for nfv
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2023:6583Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6901Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7077Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1404
- https://access.redhat.com/errata/RHSA-2024:4823
- https://access.redhat.com/errata/RHSA-2024:4831
- https://access.redhat.com/security/cve/CVE-2023-33951Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2218195Issue Tracking, Patch
- https://www.zerodayinitiative.com/advisories/ZDI-CAN-20110/Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2023:6583Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6901Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7077Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1404
- https://access.redhat.com/errata/RHSA-2024:4823
- https://access.redhat.com/errata/RHSA-2024:4831
- https://access.redhat.com/security/cve/CVE-2023-33951Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2218195Issue Tracking, Patch
- https://www.zerodayinitiative.com/advisories/ZDI-CAN-20110/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.