CVE Vulnerabilities

CVE-2022-0175

Missing Initialization of Resource

Published: Aug 26, 2022 | Modified: Nov 08, 2022
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.

Weakness

The product does not initialize a critical resource.

Affected Software

Name Vendor Start Version End Version
Virglrenderer Virglrenderer_project 0.9.0 (including) 0.9.0 (including)
Virglrenderer Virglrenderer_project 0.9.1 (including) 0.9.1 (including)

Potential Mitigations

References