Severity
7.8
High severity
Details
- CVSS score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Overview
About vulnerability
The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in the way memory objects were handled when they were being used to store a surface. When running inside a VMware guest with 3D acceleration enabled, a local, unprivileged user could potentially use this flaw to escalate their privileges.Details
- Affected product:
- AlmaLinux 9.2 ESU , CentOS 6 ELS , CentOS 7 ELS , CentOS 8.4 ELS , CentOS 8.5 ELS , CentOS Stream 8 ELS , CloudLinux 6 ELS , CloudLinux 7 ELS , Oracle Linux 6 ELS , TuxCare 9.6 ESU , Ubuntu 16.04 ELS , Ubuntu 18.04 ELS
- Affected packages:
- kernel @ 3.10.0 (+13 more)
Fixes
KernelCare state
Live-patch status from KernelCare for each operating system.
| Operating system | Status | Covered kernels |
|---|---|---|
| AlmaLinux 8 | Released |
12 kernels
|
| AlmaLinux 9 | Released |
11 kernels
|
| CloudLinux OS 7h | Released |
18 kernels
|
| CloudLinux OS 8 | Released |
17 kernels
|
| Debian 12 | Planned | — |
| Oracle Linux 9 | Released |
14 kernels
|
| RHEL 8 | Released |
11 kernels
|
| RHEL 9 | Released |
11 kernels
|
| Rocky Linux 8 | Released |
11 kernels
|
| Rocky Linux 9 | Released |
11 kernels
|