Lucene search

K
redhatcveRedhat.comRH:CVE-2023-33951
HistoryJun 28, 2023 - 12:47 p.m.

CVE-2023-33951

2023-06-2812:47:08
redhat.com
access.redhat.com
6
race condition
vmwgfx
linux kernel
gem objects
improper locking
local privileged user
disclosure
mitigation

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

0.0004 Low

EPSS

Percentile

16.1%

A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. The issue results from improper locking when performing operations on an object. This flaw allows a local privileged user to disclose information in the context of the kernel.

Mitigation

This flaw can be mitigated by preventing the affected vmwgfx kernel module from being loaded. For instructions on how to blacklist a kernel module, please see <https://access.redhat.com/solutions/41278&gt;.

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

0.0004 Low

EPSS

Percentile

16.1%