CVE-2023-52648 is a moderate-severity flaw in the Linux kernel's VMware graphics driver, drm/vmwgfx, that can let a local user trigger a denial of service through a kernel null-pointer dereference. When a plane state changes, the driver can unreference a cached surface without clearing its mapped-state flag, leaving duplicated plane-state data inconsistent; cleanup can then crash the kernel. The issue was observed with KDE KWin 6.0 on Wayland and affects code introduced in Linux kernel 5.19.
The defect is fixed in upstream Linux kernel versions 6.6.24, 6.7.12, 6.8.3, and 6.9-rc1. Red Hat assigned CVSS 3.1 score 5.5 and released corrected kernel packages for Red Hat Enterprise Linux 8 and 9, including RHEL 9.4 Extended Update Support; the RHEL 9 kernel-rt package remained affected, while RHEL 6 and 7 were outside support scope. Organizations should deploy current vendor kernel updates rather than cherry-picking the individual patch.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:5101 for the RHEL 8 kernel and RHSA-2024:5102 for the RHEL 8 kernel-rt, addressing CVE-2023-52648.
Zack Miele reported Red Hat tracking bug 2278539 for CVE-2023-52648; Fedora was separately tracked as affected through bug 2278540.
Red Hat released RHSA-2025:2270 to address CVE-2023-52648 in the Red Hat Enterprise Linux 9.4 Extended Update Support kernel.
Red Hat released RHSA-2024:9315 to address CVE-2023-52648 in the Red Hat Enterprise Linux 9 kernel.
The remediation, which unmaps the surface and resets its mapped-state flag before plane-state reset, was included in Linux kernel 6.6.24, 6.7.12, 6.8.3, and 6.9-rc1.
The Linux kernel CVE team assigned CVE-2023-52648 to the drm/vmwgfx flaw. The issue can cause a local kernel crash when inconsistent duplicated plane state is cleaned up, including crashes observed with KDE KWin 6.0 on Wayland.
A defect was introduced in Linux kernel 5.19 in which vmwgfx could unreference a plane-state surface without clearing its mapped-state flag, potentially leading to a null-pointer dereference during cleanup.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.