Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-0135
HistoryFeb 01, 2022 - 12:00 a.m.

CVE-2022-0135

2022-02-0100:00:00
ubuntu.com
ubuntu.com
20
cve-2022-0135
virgl
virtual opengl
denial of service
code execution
bugzilla redhat

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

15.7%

An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer
(virglrenderer). This flaw allows a malicious guest to create a specially
crafted virgil resource and then issue a VIRTGPU_EXECBUFFER ioctl, leading
to a denial of service or possible code execution.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchvirglrenderer< anyUNKNOWN
ubuntu20.04noarchvirglrenderer< 0.8.2-1ubuntu1.1UNKNOWN
ubuntu21.10noarchvirglrenderer< 0.8.2-5ubuntu0.21.10.1UNKNOWN
ubuntu22.04noarchvirglrenderer< 0.9.1-1~exp1ubuntu2UNKNOWN
ubuntu22.10noarchvirglrenderer< 0.9.1-1~exp1ubuntu2UNKNOWN
ubuntu23.04noarchvirglrenderer< 0.9.1-1~exp1ubuntu2UNKNOWN
ubuntu23.10noarchvirglrenderer< 0.9.1-1~exp1ubuntu2UNKNOWN
ubuntu24.04noarchvirglrenderer< 0.9.1-1~exp1ubuntu2UNKNOWN

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

15.7%