CVE-2022-0175

Name
CVE-2022-0175
Description
A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://security-tracker.debian.org/tracker/CVE-2022-0175
MISC https://bugzilla.redhat.com/show_bug.cgi?id=2039003
MISC https://gitlab.freedesktop.org/virgl/virglrenderer/-/merge_requests/654
MISC https://gitlab.freedesktop.org/virgl/virglrenderer/-/commit/b05bb61f454eeb8a85164c8a31510aeb9d79129c
MISC https://access.redhat.com/security/cve/CVE-2022-0175
Third Party Advisory https://security.gentoo.org/glsa/202210-05

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:virglrenderer_project:virglrenderer:*:*:*:*:*:*:*:* virglrenderer >= 0.9.0 <= None
cpe:2.3:a:virglrenderer_project:virglrenderer:0.9.1:*:*:*:*:*:*:* virglrenderer == None == 0.9.1
cpe:2.3:a:virglrenderer_project:virglrenderer:0.9.0:*:*:*:*:*:*:* virglrenderer == None == 0.9.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
virglrenderer 3.16-community 0.9.1-r0 Fernando Casas Schossow <casasfernando@outlook.com> possibly vulnerable
virglrenderer 3.17-community 0.10.3-r0 Fernando Casas Schossow <casasfernando@outlook.com> fixed
virglrenderer edge-community 0.10.4-r0 Fernando Casas Schossow <casasfernando@outlook.com> fixed
virglrenderer 3.18-community 0.10.4-r0 Fernando Casas Schossow <casasfernando@outlook.com> fixed