Severity
5.5MEDIUM
EPSS
0.0%
top 84.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 9
Latest updateMay 22

Description

An out-of-bounds(OOB) memory access vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_kms.c in GPU component in the Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:HExploitability: 2.1 | Impact: 4.2

Affected Packages4 packages

CVEListV5linux/kernelv3.2-rc15.13.0-52*
NVDlinux/linux_kernel3.25.13.0-52
Debianlinux< 5.10.162-1+3
Ubuntulinux-oem-6.0< 6.0.0-1014.14

Also affects: Debian Linux 11.0

🔴Vulnerability Details

11
OSV
linux-gcp, linux-hwe-5.19 vulnerabilities2023-05-22
OSV
linux, linux-aws, linux-azure, linux-azure-5.19, linux-kvm, linux-lowlatency, linux-raspi vulnerabilities2023-05-16
OSV
linux-oem-6.0 vulnerabilities2023-04-19
OSV
linux-gcp vulnerabilities2023-04-11
OSV
linux-intel-iotg vulnerabilities2023-04-11

📋Vendor Advisories

28
Ubuntu
Linux kernel vulnerabilities2023-05-22
Ubuntu
Linux kernel vulnerabilities2023-05-18
Ubuntu
Linux kernel vulnerabilities2023-05-16
Ubuntu
Linux kernel (Qualcomm Snapdragon) vulnerabilities2023-04-19
Ubuntu
Linux kernel (OEM) vulnerabilities2023-04-19
CVE-2022-36280 (MEDIUM CVSS 5.5) | An out-of-bounds(OOB) memory access | cvebase.io