CVE-2022-0175
published 2022-08-26CVE-2022-0175: A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory…
medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | virglrenderer | — | — |
| msrc | azl3_virglrenderer_0.9.1-3_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| redhat | enterprise_linux | — | — |
| virglrenderer_project | virglrenderer | — | — |
| virglrenderer_project | virglrenderer | — | — |
| virglrenderer_project | virglrenderer | — | — |
| virglrenderer_project | virglrenderer | >= 0 < 0.8.2-1ubuntu1.1 | 0.8.2-1ubuntu1.1 |
| virglrenderer_project | virglrenderer | >= 0 < 0.9.1-1~exp1ubuntu2 | 0.9.1-1~exp1ubuntu2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv7.8HIGH
cisa8.0HIGH
Microsoft
A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw
vendor_msrc·2022-08-09·CVSS 5.5
CVE-2022-0175 [MEDIUM] CWE-909 A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw
A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host possibly leading to information disclosure.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX i
CISA
Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
cisa·2022-03-03·CVSS 8.0
CVE-2018-0175 [HIGH] CWE-119 Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
Vulnerability: Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
Affected: Cisco IOS, XR, and XE Software
Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-0175
Remediation Due Date: 2022-03-17
Ubuntu
virglrenderer vulnerabilities
vendor_ubuntu·2022-02-28·CVSS 7.8
CVE-2022-0175 [HIGH] virglrenderer vulnerabilities
Title: virglrenderer vulnerabilities
Summary: Several security issues were fixed in virglrenderer.
It was discovered that virglrenderer incorrectly handled memory. An
attacker inside a guest could use this issue to cause virglrenderer to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2022-0135)
It was discovered that virglrenderer incorrectly initialized memory. An
attacker inside a guest could possibly use this issue to obtain sensitive
host information. (CVE-2022-0175)
Instructions: After a standard system update you need to restart all virtual machines to
make all the necessary changes.
Debian
CVE-2022-0175: virglrenderer - A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl...
vendor_debian·2022·CVSS 5.5
CVE-2022-0175 [MEDIUM] CVE-2022-0175: virglrenderer - A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl...
A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Red Hat
virglrenderer: memory initialization issue in vrend_resource_alloc_buffer() can lead to info leak
vendor_redhat·2021-12-14·CVSS 5.5
CVE-2022-0175 [MEDIUM] CWE-909 virglrenderer: memory initialization issue in vrend_resource_alloc_buffer() can lead to info leak
virglrenderer: memory initialization issue in vrend_resource_alloc_buffer() can lead to info leak
A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.
A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.
Statement: This flaw does not affect Red Hat Ente
GHSA
GHSA-28q3-mx7c-4cc3: A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer)
ghsa_unreviewed·2022-08-27
CVE-2022-0175 [MEDIUM] CWE-909 GHSA-28q3-mx7c-4cc3: A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer)
A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.
OSV
virglrenderer vulnerabilities
osv·2022-02-28·CVSS 7.8
CVE-2022-0135 [HIGH] virglrenderer vulnerabilities
virglrenderer vulnerabilities
It was discovered that virglrenderer incorrectly handled memory. An
attacker inside a guest could use this issue to cause virglrenderer to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2022-0135)
It was discovered that virglrenderer incorrectly initialized memory. An
attacker inside a guest could possibly use this issue to obtain sensitive
host information. (CVE-2022-0175)
OSV
CVE-2022-0175: A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer)
osv·2022-02-01·CVSS 5.5
CVE-2022-0175 [MEDIUM] CVE-2022-0175: A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer)
A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2022-0175https://bugzilla.redhat.com/show_bug.cgi?id=2039003https://gitlab.freedesktop.org/virgl/virglrenderer/-/commit/b05bb61f454eeb8a85164c8a31510aeb9d79129chttps://gitlab.freedesktop.org/virgl/virglrenderer/-/merge_requests/654https://security-tracker.debian.org/tracker/CVE-2022-0175https://security.gentoo.org/glsa/202210-05https://access.redhat.com/security/cve/CVE-2022-0175https://bugzilla.redhat.com/show_bug.cgi?id=2039003https://gitlab.freedesktop.org/virgl/virglrenderer/-/commit/b05bb61f454eeb8a85164c8a31510aeb9d79129chttps://gitlab.freedesktop.org/virgl/virglrenderer/-/merge_requests/654https://security-tracker.debian.org/tracker/CVE-2022-0175https://security.gentoo.org/glsa/202210-05
2022-08-26
Published