CVE-2022-0175Missing Initialization of Resource in Project Virglrenderer

Severity
5.5MEDIUMNVD
OSV7.8CISA8.0
EPSS
0.1%
top 67.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 26
Latest updateAug 27

Description

A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

Ubuntuvirglrenderer_project/virglrenderer< 0.8.2-1ubuntu1.1+1
CVEListV5virglrenderer_project/virglrendererAffects v0.9.0 and later.

Also affects: Enterprise Linux 8.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-28q3-mx7c-4cc3: A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer)2022-08-27
CVEList
CVE-2022-0175: A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer)2022-08-26
OSV
virglrenderer vulnerabilities2022-02-28
OSV
CVE-2022-0175: A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer)2022-02-01

📋Vendor Advisories

5
Microsoft
A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw2022-08-09
CISA
Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability2022-03-03
Ubuntu
virglrenderer vulnerabilities2022-02-28
Debian
CVE-2022-0175: virglrenderer - A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl...2022
Red Hat
virglrenderer: memory initialization issue in vrend_resource_alloc_buffer() can lead to info leak2021-12-14
CVE-2022-0175 — Missing Initialization of Resource | cvebase