PT-2023-4400 · Intel · Intel Onevpl Gpu

Cody Jackson

·

Published

2023-08-08

·

Updated

2023-11-08

·

CVE-2023-22338

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Intel oneVPL GPU versions prior to 22.6.5
Description The issue is related to an out-of-bounds read in the Intel oneVPL GPU software, which can potentially allow an authenticated user to enable information disclosure via local access. This is due to a buffer overflow in memory.
Recommendations For versions prior to 22.6.5, update to version 22.6.5 or later to resolve the issue. As a temporary workaround, consider restricting local access to the system to minimize the risk of exploitation.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2023-04745
CVE-2023-22338

Affected Products

Intel Onevpl Gpu