CVE Vulnerabilities

CVE-2022-0175

Missing Initialization of Resource

Published: Aug 26, 2022 | Modified: Nov 08, 2022
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Ubuntu
MEDIUM

A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.

Weakness

The product does not initialize a critical resource.

Affected Software

Name Vendor Start Version End Version
Virglrenderer Virglrenderer_project 0.9.0 (including) 0.9.0 (including)
Virglrenderer Virglrenderer_project 0.9.1 (including) 0.9.1 (including)
Virglrenderer Ubuntu bionic *
Virglrenderer Ubuntu devel *
Virglrenderer Ubuntu esm-apps/bionic *
Virglrenderer Ubuntu focal *
Virglrenderer Ubuntu impish *
Virglrenderer Ubuntu jammy *
Virglrenderer Ubuntu kinetic *
Virglrenderer Ubuntu lunar *
Virglrenderer Ubuntu mantic *
Virglrenderer Ubuntu noble *
Virglrenderer Ubuntu oracular *
Virglrenderer Ubuntu trusty *
Virglrenderer Ubuntu xenial *

Potential Mitigations

References