CVE-2023-5633 is a high-severity use-after-free vulnerability affecting Linux and Red Hat systems when running as a VMware guest with 3D acceleration enabled. This flaw, stemming from incomplete fixes for prior CVEs, allows a local, unprivileged user to escalate privileges. With a CVSS score of 7.8, it presents a significant risk for confidentiality, integrity, and availability. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, indicating no active exploitation. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.1.13, < 6.1.75CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.5.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.6CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.6:rc1:*:*:*:*:*:* | ||
6.6CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.6:rc2:*:*:*:*:*:* | ||
6.6CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.6:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-5633
Nov 14, 2023Kernel: vmwgfx: reference count issue leads to use-after-free in surface handling
Oct 10, 2023kernel: vmwgfx: reference count issue leads to use-after-free in surface handling
Sep 28, 2023