A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. The issue results from improper locking when performing operations on an object. This flaw allows a local privileged user to disclose information in the context of the kernel.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:LLinux Kernel
OSLinux≤ 6.3.9Red Hat Enterprise Linux
OSRedhat8.09.0Red Hat Enterprise Linux For Real Time
OSRedhat8.0Red Hat Enterprise Linux For Real Time For Nfv
OSRedhat8.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPERace Condition
References
Related vulnerabilities
CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
CVE-2022-47986CRITICAL9.8⚠ KEVPL ✓same product
RCE przez YAML deserialization w IBM Aspera Faspex
CVE-2022-22954CRITICAL9.8⚠ KEVPL ✓same product
RCE w VMware Workspace ONE Access i Identity Manager poprzez server-side template injection