CVE-2023-33951 is a moderate-severity race condition in the Linux kernel’s vmwgfx driver affecting its handling of GEM objects. Improper locking can allow a local, highly privileged attacker to disclose kernel-context information, with Red Hat also assessing a low availability impact. Red Hat assigned a CVSS v3.1 score of 6.7; NVD scored it 5.3, reflecting a higher assessed attack complexity.
Red Hat released fixes through errata for affected Red Hat Enterprise Linux 8 and 9 kernel package streams between November 2023 and July 2024. RHEL 9 kernel-rt remains listed as affected. Organizations should apply the relevant kernel updates and, where patching is not immediately possible, prevent the vmwgfx kernel module from loading.

See affected versions and whether adversaries are exploiting it.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.