Back

MEDIUM

There is an out-of-bounds write vulnerability in vmwgfx driver

Published Sep 9, 2022

Description

An out-of-bounds(OOB) memory access vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_kms.c in GPU component in the Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).

Affected products

Remediation

Red Hat statement

Systems making use of the vmwgfx driver are potentially affected by this flaw; systems without the vmwgfx driver loaded are not affected by this flaw.

Red Hat mitigation

To mitigate this issue, it is possible to prevent the affected code from being loaded by blacklisting the vmwgfx kernel module. For instructions relating to blacklisting a kernel module, please see https://access.redhat.com/solutions/41278.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Anolis
Published Sep 9, 2022
Updated Sep 17, 2024
Reserved Sep 7, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 9, 2022
ENISA EUVD
Assigner Anolis
Published Sep 9, 2022
Updated Sep 17, 2024
Exploited since n/a
EUVD-2022-38997