CVE-2022-38457

CWE-416Use After Free7 documents7 sources
Severity
5.5MEDIUM
EPSS
0.0%
top 87.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 9
Latest updateSep 13

Description

A use-after-free(UAF) vulnerability was found in function 'vmw_cmd_res_check' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in Linux kernel's vmwgfx driver with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:HExploitability: 2.1 | Impact: 4.2

Affected Packages3 packages

CVEListV5linux/kernelv4.20-rc15.13.0-52*
NVDlinux/linux_kernel4.206.1.7+1
Debianlinux< 6.1.7-1+2

🔴Vulnerability Details

3
GHSA
GHSA-24v2-x6vh-5fpj: A use-after-free(UAF) vulnerability was found in function 'vmw_cmd_res_check' in drivers/gpu/vmxgfx/vmxgfx_execbuf2022-09-10
OSV
CVE-2022-38457: A use-after-free(UAF) vulnerability was found in function 'vmw_cmd_res_check' in drivers/gpu/vmxgfx/vmxgfx_execbuf2022-09-09
CVEList
There is an UAF vulnerability in vmwgfx driver2022-09-09

📋Vendor Advisories

3
Microsoft
There is an UAF vulnerability in vmwgfx driver2022-09-13
Red Hat
kernel: vmwgfx: use-after-free in vmw_cmd_res_check2022-09-09
Debian
CVE-2022-38457: linux - A use-after-free(UAF) vulnerability was found in function 'vmw_cmd_res_check' in...2022
CVE-2022-38457 (MEDIUM CVSS 5.5) | A use-after-free(UAF) vulnerability | cvebase.io