5.5
CVE-2022-0175
- EPSS 0.04%
- Published 26.08.2022 18:15:08
- Last modified 21.11.2024 06:38:04
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.
Data is provided by the National Vulnerability Database (NVD)
Virglrenderer Project ≫ Virglrenderer Version0.9.0
Virglrenderer Project ≫ Virglrenderer Version0.9.1
Redhat ≫ Enterprise Linux Version8.0 SwEditionadvanced_virtualization
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.121 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-909 Missing Initialization of Resource
The product does not initialize a critical resource.