A double-free vulnerability was found in handling vmw_buffer_object objects in the vmwgfx driver in the Linux kernel. This issue occurs due to the lack of validating the existence of an object prior to performing further free operations on the object, which may allow a local privileged user to escalate privileges and execute code in the context of the kernel.
History

Thu, 26 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2023-07-24T15:19:18.913Z

Updated: 2026-02-25T17:20:10.731Z

Reserved: 2023-05-24T07:11:47.572Z

Link: CVE-2023-33952

cve-icon Vulnrichment

Updated: 2024-08-02T15:54:14.153Z

cve-icon NVD

Status : Modified

Published: 2023-07-24T16:15:11.893

Modified: 2024-11-21T08:06:16.840

Link: CVE-2023-33952

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-02-15T00:00:00Z

Links: CVE-2023-33952 - Bugzilla