CVE-2023-33951
A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. The issue results from improper locking when performing operations on an object. This flaw allows a local privileged user to disclose information in the context of the kernel.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.7
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
- EPSS probability
- 0.01%
- CWE
- CWE-413
- Published
- 2023-07-24
- Last modified
- 2026-03-13
Affected products
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 8.8 Extended Update Support
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support
- Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support
Weakness type
Related vulnerabilities
- CVE-2026-44608 — Use after free and crash under special conditions in RPZ code
- CVE-2026-32748 — Squid has Denial of Service in ICP Response handling
- CVE-2025-69198 — Pterodactyl's improper resource locking allows raced queries to create more resources than alloted
- CVE-2025-0003 — Inadequate lock protection within Xilinx Run time may allow a local attacker to trigger a...
- CVE-2025-3450 — Automation Runtime SDM requests may impact system
- CVE-2023-32253 — Kernel: deadlock in ksmbd_find_crypto_ctx()
- CVE-2022-49737 — In X.Org X server 20.11 through 21.1.16, when a client application uses easystroke for mouse...
- CVE-2023-2430 — A vulnerability was found due to missing lock for IOPOLL flaw in io_cqring_event_overflow() in...