cbcvebase.
CVE-2022-0135
published 2022-08-25

CVE-2022-0135: An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a specially crafted…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a specially crafted virgil resource and then issue a VIRTGPU_EXECBUFFER ioctl, leading to a denial of service or possible code execution.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianvirglrenderer< virglrenderer 0.10.0-1 (bookworm)virglrenderer 0.10.0-1 (bookworm)
googlechrome_chrome
msrcazl3_virglrenderer_0.9.1-3_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
redhatenterprise_linux
virglrenderer_projectvirglrenderer
virglrenderer_projectvirglrenderer>= 0 < 0.8.2-5+deb11u10.8.2-5+deb11u1
virglrenderer_projectvirglrenderer>= 0 < 0.10.0-10.10.0-1
virglrenderer_projectvirglrenderer>= 0 < 0.10.0-10.10.0-1
virglrenderer_projectvirglrenderer>= 0 < 0.10.0-10.10.0-1
virglrenderer_projectvirglrenderer>= 0 < 0.8.2-1ubuntu1.10.8.2-1ubuntu1.1
virglrenderer_projectvirglrenderer>= 0.8.1 < 0.10.00.10.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH