Lucene search

K
rosalinuxROSA LABROSA-SA-2023-2267
HistoryOct 22, 2023 - 5:46 a.m.

Advisory ROSA-SA-2023-2267

2023-10-2205:46:59
ROSA LAB
abf.rosalinux.ru
9
virglrenderer
rosa-chrome
out-of-bounds
vulnerability
denial of service
code execution
ioctl virtgpu_execbuffer
package update
rosa-sa-2023-2267

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

15.7%

software: virglrenderer 0.8.1
OS: ROSA-CHROME

package_evr_string: virglrenderer-0.8.1-3.src.rpm

CVE-ID: CVE-2022-0135
BDU-ID: 2023-05686
CVE-Crit: HIGH
CVE-DESC.: An out-of-bounds write issue has been discovered in the OpenGL VirGL virtual visualization tool (virglrenderer). This vulnerability allows an attacker to create a specially crafted Virgil resource and then issue an ioctl VIRTGPU_EXECBUFFER, resulting in a denial of service or possible code execution.
CVE-STATUS: Fixed
CVE-REV: To close, run the command: sudo dnf update virglrenderer

OSVersionArchitecturePackageVersionFilename
ROSAanynoarchvirglrenderer< 0.8.1UNKNOWN

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

15.7%