CVE-2023-5633 is a high-severity use-after-free flaw in the Linux kernel's vmwgfx graphics driver. Improper reference-count updates in surface memory-object handling—introduced through fixes for CVE-2023-33951 and CVE-2023-33952—can allow a local unprivileged attacker to escalate privileges in VMware guest systems with 3D acceleration enabled. Red Hat rates the issue CVSS 7.8 and maps it to CWE-911, improper update of reference count.
The upstream remediation is commit 91398b413d03660fd5828f7b4abc64e884b98069; Fedora included a fix in its 6.5.8 stable kernel update, and Red Hat released updated kernel packages for affected RHEL 8, RHEL 9, 8.8 EUS, and 9.2 EUS systems. RHEL 9 kernel-rt remains affected; organizations unable to patch should disable VMware 3D acceleration or prevent the vmwgfx module from loading.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:0113 for the RHEL 8 kernel and RHSA-2024:0134 for the RHEL 8 kernel-rt package, fixing CVE-2023-5633.
Mauro Matteo Cascella reported CVE-2023-5633, a vmwgfx surface-handling reference-count flaw that can cause use-after-free and potential local privilege escalation in VMware guests with 3D acceleration enabled.
Red Hat released RHSA-2024:4823 for the RHEL 9.2 Extended Update Support kernel and RHSA-2024:4831 for kernel-rt, addressing CVE-2023-5633.
Red Hat released RHSA-2024:1404 to fix CVE-2023-5633 in the RHEL 8.8 Extended Update Support kernel.
Red Hat addressed CVE-2023-5633 in the RHEL 9 kernel through advisory RHSA-2024:0461.
Fedora addressed CVE-2023-5633 in its Linux 6.5.8 stable kernel update.
The issue was fixed upstream in Linux kernel 6.6-rc6 through commit 91398b413d03660fd5828f7b4abc64e884b98069.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.