CVE-2022-38096

Severity
5.5MEDIUM
EPSS
0.0%
top 89.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 9
Latest updateApr 3

Description

A NULL pointer dereference vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:HExploitability: 2.1 | Impact: 4.2

Affected Packages38 packages

CVEListV5linux/kernelv4.20-rc15.13.0-52*
Debianlinux< 5.10.215-1+3
Ubuntulinux< 5.4.0-204.224+2
Ubuntulinux-aws< 5.4.0-1137.147+2

🔴Vulnerability Details

22
OSV
linux-iot vulnerabilities2025-04-03
OSV
linux-raspi-5.4 vulnerabilities2025-01-15
OSV
linux-azure-5.4 vulnerabilities2025-01-14
OSV
linux-azure vulnerabilities2025-01-09
OSV
linux-aws, linux-aws-5.4, linux-bluefield, linux-ibm, linux-ibm-5.4, linux-oracle, linux-oracle-5.4, linux-xilinx-zynqmp vulnerabilities2024-12-20

📋Vendor Advisories

21
Ubuntu
Linux kernel (IoT) vulnerabilities2025-04-03
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2025-01-15
Ubuntu
Linux kernel (Azure) vulnerabilities2025-01-14
Ubuntu
Linux kernel (Azure) vulnerabilities2025-01-09
Ubuntu
Linux kernel vulnerabilities2024-12-20
CVE-2022-38096 (MEDIUM CVSS 5.5) | A NULL pointer dereference vulnerab | cvebase.io