Back

HIGH

Kernel: vmwgfx: reference count issue leads to use-after-free in surface handling

Published Oct 23, 2023

Description

The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in the way memory objects were handled when they were being used to store a surface. When running inside a VMware guest with 3D acceleration enabled, a local, unprivileged user could potentially use this flaw to escalate their privileges.

Affected products

Remediation

Vendor solution

This flaw can be mitigated by turning off 3D acceleration in VMware (if possible) or preventing the affected `vmwgfx` kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278.

Red Hat mitigation

This flaw can be mitigated by turning off 3D acceleration in VMware (if possible) or preventing the affected `vmwgfx` kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 23, 2023
Updated Feb 25, 2026
Reserved Oct 18, 2023
CISA Vulnrichment
Updated May 10, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Sep 28, 2023