# CVE-2023-33951

## Summary

- **CVE ID:** CVE-2023-33951
- **Severity:** MEDIUM
- **CVSS Score:** 6.7 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L)
- **CWE:** CWE-413
- **Published:** Jul 24, 2023
- **Last Modified:** Mar 13, 2026

## Description

A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. The issue results from improper locking when performing operations on an object. This flaw allows a local privileged user to disclose information in the context of the kernel.

## Affected Products

- Red Hat — Red Hat Enterprise Linux 8 (0:4.18.0-513.5.1.rt7.307.el8_9)
- Red Hat — Red Hat Enterprise Linux 8 (0:4.18.0-513.5.1.el8_9)
- Red Hat — Red Hat Enterprise Linux 8.8 Extended Update Support (0:4.18.0-477.51.1.el8_8)
- Red Hat — Red Hat Enterprise Linux 9 (0:5.14.0-362.8.1.el9_3)
- Red Hat — Red Hat Enterprise Linux 9.2 Extended Update Support (0:5.14.0-284.75.1.el9_2)
- Red Hat — Red Hat Enterprise Linux 9.2 Extended Update Support (0:5.14.0-284.75.1.rt14.360.el9_2)

## References

- [CNA](https://access.redhat.com/errata/RHSA-2023:6583)
- [CNA](https://access.redhat.com/errata/RHSA-2023:6901)
- [CNA](https://access.redhat.com/errata/RHSA-2023:7077)
- [CNA](https://access.redhat.com/errata/RHSA-2024:1404)
- [CNA](https://access.redhat.com/errata/RHSA-2024:4823)
- [CNA](https://access.redhat.com/errata/RHSA-2024:4831)
- [CNA](https://access.redhat.com/security/cve/CVE-2023-33951)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=2218195)
- [CNA](https://www.zerodayinitiative.com/advisories/ZDI-CAN-20110/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.01%
- **EPSS Percentile:** 0.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._