The reference count changes made as part of the CVE-2023...
High severity
Unreviewed
Published
Oct 24, 2023
to the GitHub Advisory Database
•
Updated Jul 24, 2024
Description
Published by the National Vulnerability Database
Oct 23, 2023
Published to the GitHub Advisory Database
Oct 24, 2023
Last updated
Jul 24, 2024
The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in the way memory objects were handled when they were being used to store a surface. When running inside a VMware guest with 3D acceleration enabled, a local, unprivileged user could potentially use this flaw to escalate their privileges.
References