5.5
CVE-2022-0175
- EPSS 0.04%
- Veröffentlicht 26.08.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:38:04
- Quelle secalert@redhat.com
- Teams Watchlist Login
- Unerledigt Login
A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Virglrenderer Project ≫ Virglrenderer Version0.9.0
Virglrenderer Project ≫ Virglrenderer Version0.9.1
Redhat ≫ Enterprise Linux Version8.0 SwEditionadvanced_virtualization
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.121 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-909 Missing Initialization of Resource
The product does not initialize a critical resource.