Kernel: vmwgfx: reference count issue leads to use-after-free in surface handling
Published Oct 23, 2023
7.8
HIGHCVSS 3.1
EPSS 0.28%
Description
The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in the way memory objects were handled when they were being used to store a surface. When running inside a VMware guest with 3D acceleration enabled, a local, unprivileged user could potentially use this flaw to escalate their privileges.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 9 | affected |
|
Configuration 1
- ≥ 6.1.13 · < 6.1.75
- ≥ 6.2 · < 6.5.8
- 6.6
- 6.6
- 6.6
- 6.6
- 6.6
- 6.6
Configuration 2
- 8.0
- 9.0
- 8.8
- 9.2
- 9.4
- 8.0_aarch64
- 9.0_aarch64
- 8.8_aarch64
- 9.2_aarch64
- 9.4_aarch64
- 9.0_s390x
- 9.2_s390x
- 9.4_s390x
- 8.0_ppc64le
- 9.0_ppc64le
- 8.8_ppc64le
- 9.2_ppc64le
- 9.4_ppc64le
- 8.0
- 9.0
- 8.8
- 9.2
- 9.4
- 8.0_aarch64
- 9.0_aarch64
- 8.8_aarch64
- 9.2_aarch64
- 9.4_aarch64
- 8.0_s390x
- 9.0_s390x
- 8.8_s390x
- 9.2_s390x
- 9.4_s390x
- 8.0_ppc64le
- 9.0_ppc64le
- 9.2_ppc64le
- 9.4_ppc64le
- 8.0
- 9.0
- 8.0
- 9.0
- 9.2
- 9.4
- 8.8
- 9.2_ppc64le
- 8.8
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-513.11.1.el8_9
Fixed · RHSA-2024:0113
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-513.11.1.rt7.313.el8_9
Fixed · RHSA-2024:0134
Red Hat Enterprise Linux 8.8 Extended Update Support
kernel-0:4.18.0-477.51.1.el8_8
Fixed · RHSA-2024:1404
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.18.1.el9_3
Fixed · RHSA-2024:0461
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.18.1.el9_3
Fixed · RHSA-2024:0461
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-0:5.14.0-284.75.1.el9_2
Fixed · RHSA-2024:4823
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-rt-0:5.14.0-284.75.1.rt14.360.el9_2
Fixed · RHSA-2024:4831
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.11.1.el8_9 | Fixed | RHSA-2024:0113 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-513.11.1.rt7.313.el8_9 | Fixed | RHSA-2024:0134 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.51.1.el8_8 | Fixed | RHSA-2024:1404 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.18.1.el9_3 | Fixed | RHSA-2024:0461 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.18.1.el9_3 | Fixed | RHSA-2024:0461 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-0:5.14.0-284.75.1.el9_2 | Fixed | RHSA-2024:4823 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-rt-0:5.14.0-284.75.1.rt14.360.el9_2 | Fixed | RHSA-2024:4831 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
This flaw can be mitigated by turning off 3D acceleration in VMware (if possible) or preventing the affected `vmwgfx` kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278.
Red Hat mitigation
This flaw can be mitigated by turning off 3D acceleration in VMware (if possible) or preventing the affected `vmwgfx` kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed May 10, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (7 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.28% (0.00280) | 18.45th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.28% (0.00282) | 19.70th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.07% (0.00068) | 18.10th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 5.07th | v3 (v2023.03.01) |
| Apr 16, 2024 | 0.04% (0.00042) | 5.28th | v3 (v2023.03.01) |
| Nov 3, 2023 | 0.04% (0.00043) | 7.28th | v3 (v2023.03.01) |
| Oct 24, 2023 | 0.05% (0.00050) | 17.43th | v3 (v2023.03.01) |
References (10)
- https://access.redhat.com/errata/RHSA-2024:0113 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0134 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0461 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1404 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:4823 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:4831 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-5633 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2245663 issue-trackingx_refsource_REDHATIssue TrackingPatch
- https://nvd.nist.gov/vuln/detail/CVE-2023-5633
- https://www.cve.org/CVERecord?id=CVE-2023-5633
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2024:0113 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2024:0134 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2024:0461 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2024:1404 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2024:4823 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2024:4831 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2023-5633 | vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2245663 | issue-trackingx_refsource_REDHATIssue TrackingPatch | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-5633 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-5633 |
Change history (0)
No recorded changes yet.