CVE-2023-33951

Published Jul 24, 2023

Last updated 2 months ago

Overview

Description
A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. The issue results from improper locking when performing operations on an object. This flaw allows a local privileged user to disclose information in the context of the kernel.
Source
secalert@redhat.com
NVD status
Modified
Products
linux_kernel, enterprise_linux, enterprise_linux_for_real_time, enterprise_linux_for_real_time_for_nfv

Risk scores

CVSS 3.1

Type
Primary
Base score
5.3
Impact score
4
Exploitability score
0.8
Vector string
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

secalert@redhat.com
CWE-413
nvd@nist.gov
CWE-362

Social media

Hype score
Not currently trending

Configurations