« List of all CVEs

CVE-2023-33951

Kernel: vmwgfx: race condition leading to information disclosure vulnerability

Published: 7/24/2023 Last updated: 2/18/2026 Reserved: 5/24/2023

A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. The issue results from improper locking when performing operations on an object. This flaw allows a local privileged user to disclose information in the context of the kernel.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 6.7 Medium CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

Opam packages affected (29)

albatross cdrom conf-bpftool conf-libbpf conf-linux-libc-dev core core_unix hvsock mirage-block-unix mm ocaml-probes ortools_solvers orun rawlink rawlink-eio rawlink-lwt restricted shell solo5 solo5-bindings-hvt solo5-bindings-spt solo5-cross-aarch64 solo5-kernel-ukvm tracy-client tuntap uring vhd-format vhd-format-lwt xapi-stdext-unix

Products affected (5)

Product Vendor Version
Red Hat Enterprise Linux 9 Red Hat 16.12.2s
Red Hat Enterprise Linux 9.2 Extended Update Support Red Hat 16.12.1s
Red Hat Enterprise Linux 8 Red Hat < 4.4.32.16
Red Hat Enterprise Linux 9.2 Extended Update Support Red Hat < 4.4.36.7
Red Hat Enterprise Linux 7 Red Hat < 4.4.40.37

References (36)