Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2022-0175

Published: 1 February 2022

A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.

Priority

Medium

Cvss 3 Severity Score

5.5

Score breakdown

Status

Package Release Status
virglrenderer
Launchpad, Ubuntu, Debian
bionic Needed

focal
Released (0.8.2-1ubuntu1.1)
impish
Released (0.8.2-5ubuntu0.21.10.1)
jammy
Released (0.9.1-1~exp1ubuntu2)
kinetic
Released (0.9.1-1~exp1ubuntu2)
lunar
Released (0.9.1-1~exp1ubuntu2)
mantic
Released (0.9.1-1~exp1ubuntu2)
noble
Released (0.9.1-1~exp1ubuntu2)
trusty Ignored
(end of standard support)
upstream Needs triage

xenial Ignored
(end of standard support)
Patches:
upstream: https://gitlab.freedesktop.org/virgl/virglrenderer/-/commit/b05bb61f454eeb8a85164c8a31510aeb9d79129c

Severity score breakdown

Parameter Value
Base score 5.5
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact None
Availability impact None
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N