CVE-2023-33951

A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. The issue results from improper locking when performing operations on an object. This flaw allows a local privileged user to disclose information in the context of the kernel.
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_real_time:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv:8.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-07-24 16:15

Updated : 2024-07-24 16:15


NVD link : CVE-2023-33951

Mitre link : CVE-2023-33951

CVE.ORG link : CVE-2023-33951


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • enterprise_linux_for_real_time
  • enterprise_linux_for_real_time_for_nfv

linux

  • linux_kernel
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CWE-667

Improper Locking

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor