Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2023-33951
HistoryJul 24, 2023 - 4:15 p.m.

CVE-2023-33951

2023-07-2416:15:11
Debian Security Bug Tracker
security-tracker.debian.org
17
cve-2023-33951
vulnerability
gem objects
improper locking
local privileged user
kernel disclosure
unix

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

EPSS

0

Percentile

15.9%

A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. The issue results from improper locking when performing operations on an object. This flaw allows a local privileged user to disclose information in the context of the kernel.

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

EPSS

0

Percentile

15.9%