Vulnerability Details CVE-2022-0135
An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a specially crafted virgil resource and then issue a VIRTGPU_EXECBUFFER ioctl, leading to a denial of service or possible code execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 13.5%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2022-0135
-
cpe:2.3:a:virglrenderer_project:virglrenderer:0.8.1
-
cpe:2.3:a:virglrenderer_project:virglrenderer:0.8.2
-
cpe:2.3:a:virglrenderer_project:virglrenderer:0.9.0
-
cpe:2.3:a:virglrenderer_project:virglrenderer:0.9.1
-
cpe:2.3:o:debian:debian_linux:10.0
-
cpe:2.3:o:redhat:enterprise_linux:8.0