CVE-2023-52662 is a low-severity memory-leak flaw in the Linux kernel's VMware graphics driver, drm/vmwgfx. In vmw_gmrid_man_get_node, failure of ida_alloc_max can leave kmalloc-allocated memory and resources initialized through ttm_resource_init unfreed, potentially causing a local, low-privileged user to exhaust system memory and affect availability. The issue was introduced in Linux kernel 5.14 and has a CVSS v3.1 score of 5.5.
The flaw is fixed in upstream stable kernels 5.15.153, 6.1.83, 6.6.23, 6.7.11, 6.8.2, and 6.9. Red Hat released corrected standard and real-time kernel packages for RHEL 8 and standard kernel packages for RHEL 9, including RHEL 9.4 EUS; the RHEL 9 real-time kernel fix remains deferred. RHEL 6 and RHEL 7 kernel packages are outside support scope and should be treated as affected unless mitigated or upgraded. Organizations should deploy supported updated kernel packages and reboot affected hosts.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:5101 for the RHEL 8 kernel and RHSA-2024:5102 for the RHEL 8 real-time kernel, addressing CVE-2023-52662.
Zack Miele reported CVE-2023-52662 in Red Hat's tracker, and a Fedora-wide tracking bug was created for the issue.
Red Hat released RHSA-2025:9584 to address CVE-2023-52662 in the RHEL 9.4 Extended Update Support kernel.
Red Hat released RHSA-2024:9315 to remediate CVE-2023-52662 in the standard RHEL 9 kernel. The RHEL 9 kernel-rt fix remained deferred.
The Linux kernel CVE team assigned CVE-2023-52662 to the vmwgfx memory-leak vulnerability affecting vmw_gmrid_man_get_node.
A code change in Linux kernel 5.14 introduced a resource leak in the drm/vmwgfx driver's vmw_gmrid_man_get_node function when ida_alloc_max fails after resources are allocated.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.