PT-2021-8112 · Unknown+5 · Virglrenderer+5

Michael Kaplan

·

Published

2021-11-30

·

Updated

2024-04-07

·

CVE-2022-0135

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions virglrenderer (affected versions not specified)
Description The issue is related to an out-of-bounds write in the VirGL virtual OpenGL renderer. A malicious guest can create a specially crafted virgil resource and issue a VIRTGPU EXECBUFFER ioctl, potentially leading to a denial of service or code execution. This could allow an attacker to access confidential data, compromise its integrity, and cause a service disruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2675
ALT-PU-2024-2056
ALT-PU-2024-2575
ALT-PU-2024-4825
AZL-10724
AZL-35346
BDU:2024-07306
CVE-2022-0135
DLA-3232-1
MGASA-2022-0401
OESA-2022-1890
OPENSUSE-SU-2022:0479-1
OPENSUSE-SU-2022_0479-1
OPENSUSE-SU-2022_2395-1
OPENSUSE-SU-2024:11815-1
ROSA-SA-2023-2267
SUSE-SU-2022:0478-1
SUSE-SU-2022:0479-1
SUSE-SU-2022:2395-1
SUSE-SU-2022_0478-1
SUSE-SU-2022_0479-1
SUSE-SU-2022_2395-1
USN-5309-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Suse
Ubuntu
Virglrenderer