CVE-2023-39198

Updated: 2025-08-20 00:38:16.804494

Description:

A race condition was found in the QXL driver in the Linux kernel. The qxl_mode_dumb_create() function dereferences the qobj returned by the qxl_gem_object_create_with_handle(), but the handle is the only one holding a reference to it. This flaw allows an attacker to guess the returned handle value and trigger a use-after-free issue, potentially leading to a denial of service or privilege escalation.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 6.4

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 6.4 MEDIUM Released CLSA-2025:1743193221 2024-06-24 11:27:55
CentOS 6 ELS kernel 2.6.32 6.4 MEDIUM Ignored 2023-11-20 04:07:50 Ignored due to low severity
CentOS 7 ELS kernel 3.10.0 6.4 MEDIUM Ignored 2023-11-20 04:07:50 Ignored due to low severity
CentOS 8.4 ELS kernel 4.18.0 6.4 MEDIUM Released CLSA-2023:1701963303 2023-12-07 13:09:57
CentOS 8.5 ELS kernel 4.18.0 6.4 MEDIUM Released CLSA-2023:1701962635 2023-12-07 13:09:58
CentOS Stream 8 ELS kernel 4.18.0 6.4 MEDIUM Ignored 2024-05-10 14:19:04 Ignored due to low severity
CloudLinux 6 ELS kernel 2.6.32 6.4 MEDIUM Ignored 2023-11-20 04:07:50 Ignored due to low severity
Oracle Linux 6 ELS kernel 2.6.32 6.4 MEDIUM Ignored 2023-11-20 04:07:50 Ignored due to low severity
Ubuntu 16.04 ELS linux-hwe 4.15.0 6.4 MEDIUM Ignored 2023-11-20 04:07:50 Ignored due to low severity
Ubuntu 16.04 ELS linux 4.4.0 6.4 MEDIUM Ignored 2023-11-20 04:07:50 Ignored due to low severity
Total: 11