virglrenderer: out-of-bounds write in read_transfer_data()
Published Aug 25, 2022
7.8
HIGHCVSS 3.1
EPSS 0.40%
Description
An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a specially crafted virgil resource and then issue a VIRTGPU_EXECBUFFER ioctl, leading to a denial of service or possible code execution.
Affected products
- Vendor n/a Product Virglrenderer Defaultunknown
Affected
- virglrenderer 0.8.1 and after
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Virglrenderer | unknown | Affected
|
Configuration 1
- ≥ 0.8.1 · < 0.10.0
Configuration 2
- 8.0
Configuration 3
- 10.0
No data.
Red Hat Enterprise Linux 8 Advanced Virtualization
virt:8.2/virglrenderer
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.2/virglrenderer | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw does not affect Red Hat Enterprise Linux as `virglrenderer` is not shipped in RHEL. Support for VirGL was enabled as a Technology Preview in Red Hat Enterprise Linux Advanced Virtualization 8.2 and later disabled in Red Hat Enterprise Linux Advanced Virtualization 8.3. For more information on the Technology Preview support scope, please refer to https://access.redhat.com/support/offerings/techpreview.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-0135 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2037790 Issue TrackingPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15348 Advisory
- https://lists.debian.org/debian-lts-announce/2022/12/msg00017.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-0135
- https://security.gentoo.org/glsa/202210-05 vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-0135
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-0135 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2037790 | Issue TrackingPatchThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15348 | Advisory | |
| https://lists.debian.org/debian-lts-announce/2022/12/msg00017.html | mailing-listMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-0135 | ||
| https://security.gentoo.org/glsa/202210-05 | vendor-advisoryThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-0135 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data