Skip to content

CVE-2023-33952 | kernel,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Re

A double-free vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of vmw_buffer_object objects. The issue results from the lack of validating the existence of an object prior to performing further free operations on the object. This flaw allows a local privileged user to escalate privileges and execute code in the context of the kernel..This CVE has a CVSS3.1 score of 6.3 and a Base Severity of MEDIUM.

InfoDetails
CVE IDCVE-2023-33952
CVE StatePUBLISHED
BaseScoreNA
BaseSeverityNA
VectorStringNA
VersionNA

References for CVE-2023-33952 :
https://access.redhat.com/security/cve/CVE-2023-33952
https://bugzilla.redhat.com/show_bug.cgi?id=2218212
https://www.zerodayinitiative.com/advisories/ZDI-CAN-20292

Metric TypeMetric Score
AttackVector(AV)NA
AttackComplexity(AC)NA
PrivilegesRequired(PR)NA
UserInteraction(UI)NA
Scope(S)NA
Confidentiality(C)NA
Availability(A)NA
Integrity(I)NA