cbcvebase.
CVE-2023-33952
published 2023-10-23

CVE-2023-33952: The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in the way memory objects were handled…

PriorityP430medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.46%
37.4th percentile
The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in the way memory objects were handled when they were being used to store a surface. When running inside a VMware guest with 3D acceleration enabled, a local, unprivileged user could potentially use this flaw to escalate their privileges.

Affected

62 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.15-1 (bookworm)linux 6.1.15-1 (bookworm)
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux_kernel<= 6.3.9
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.1.15-16.1.15-1
linuxlinux_kernel>= 0 < 6.5.8-16.5.8-1
linuxlinux_kernel>= 0 < 6.1.15-16.1.15-1
linuxlinux_kernel>= 0 < 6.5.8-16.5.8-1
linuxlinux_kernel>= 0 < 6.1.15-16.1.15-1
linuxlinux_kernel>= 6.1.13 < 6.1.756.1.75
linuxlinux_kernel>= 6.2 < 6.5.86.5.8
msrccbl2_hyperv-daemons_5.15.158.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.135.1-2_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
redhatcodeready_linux_builder
redhatcodeready_linux_builder
redhatcodeready_linux_builder_eus
redhatcodeready_linux_builder_eus
redhatcodeready_linux_builder_eus
redhatcodeready_linux_builder_for_arm64
redhatcodeready_linux_builder_for_arm64
redhatcodeready_linux_builder_for_arm64_eus
redhatcodeready_linux_builder_for_arm64_eus

CVSS provenance

nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
osv6.7MEDIUM
vendor_debian6.7MEDIUM
vendor_msrc6.7MEDIUM
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.