« List of all CVEs

CVE-2023-33952

Kernel: vmwgfx: double free within the handling of vmw_buffer_object objects

Published: 7/24/2023 Last updated: 2/25/2026 Reserved: 5/24/2023

A double-free vulnerability was found in handling vmw_buffer_object objects in the vmwgfx driver in the Linux kernel. This issue occurs due to the lack of validating the existence of an object prior to performing further free operations on the object, which may allow a local privileged user to escalate privileges and execute code in the context of the kernel.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 6.7 Medium CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Opam packages affected (29)

albatross cdrom conf-bpftool conf-libbpf conf-linux-libc-dev core core_unix hvsock mirage-block-unix mm ocaml-probes ortools_solvers orun rawlink rawlink-eio rawlink-lwt restricted shell solo5 solo5-bindings-hvt solo5-bindings-spt solo5-cross-aarch64 solo5-kernel-ukvm tracy-client tuntap uring vhd-format vhd-format-lwt xapi-stdext-unix

Products affected (20)

Product Vendor Version
Red Hat Enterprise Linux 9 Red Hat < c5e81e672699e0c5557b2b755cc8f7a69aa92bff
Red Hat Enterprise Linux 9 Red Hat 6.8
Red Hat Enterprise Linux 9.2 Extended Update Support Red Hat < 6.8
Red Hat Enterprise Linux 9.2 Extended Update Support Red Hat <= 5.4.*
Red Hat Enterprise Linux 6 Red Hat <= 6.16.*
Red Hat Enterprise Linux 7 Red Hat <= *
Red Hat Enterprise Linux 8 Red Hat < ffa0b64e3be58519ae472ea29a1a1ad681e32f48
Red Hat Enterprise Linux 6 Red Hat <= 5.15.*
Red Hat Enterprise Linux 7 Red Hat <= 5.16.*
Red Hat Enterprise Linux 8.8 Extended Update Support Red Hat 11.8.3
Red Hat Enterprise Linux 9 Red Hat 4.4
Red Hat Enterprise Linux 9 Red Hat < 4.4
Red Hat Enterprise Linux 8.8 Extended Update Support Red Hat < 630c0e6064daf84f17aad1a7d9ca76b562e3fe47
Red Hat Enterprise Linux 7 Red Hat 0
Red Hat Enterprise Linux 9.2 Extended Update Support Red Hat <= 5.10.*
Red Hat Enterprise Linux 7 Red Hat <= 5.17.*
Red Hat Enterprise Linux 9 Red Hat <= *
Red Hat Enterprise Linux 8 Red Hat < 77ff27ff0e4529a003c8a1c2492c111968c378d3
Red Hat Enterprise Linux 9.2 Extended Update Support Red Hat <= 6.12.*
Red Hat Enterprise Linux 8 Red Hat < cbc065efcba000ad8f615f506ebe61b6d3c5145b

References (36)