Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-0175

Опубликовано: 26 авг. 2022
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:virglrenderer_project:virglrenderer:0.9.0:*:*:*:*:*:*:*
cpe:2.3:a:virglrenderer_project:virglrenderer:0.9.1:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:advanced_virtualization:*:*:*

EPSS

Процентиль: 5%
0.00025
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-909
CWE-909

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 3 года назад

A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.

CVSS3: 6.5
redhat
больше 3 лет назад

A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.

CVSS3: 5.5
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 5.5
debian
почти 3 года назад

A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). ...

suse-cvrf
больше 3 лет назад

Security update for virglrenderer

EPSS

Процентиль: 5%
0.00025
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-909
CWE-909