Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 8: MGASA-2022-0401 Critical: Virglrenderer DoS Threat

mageia
Calendar Grey November 1, 2022
Dist Mageia Esm H88
Revised libvirt packages address critical vulnerabilities for Mageia 8, which may lead to possible code injection or service interruption.
An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer)

Summary

An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a specially crafted virgil resource and then issue a VIRTGPU_EXECBUFFER ioctl, leading to a denial of service or possible code execution. (CVE-2022-0135)
A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure. (CVE-2022-0175)

References

- https://bugs.mageia.org/show_bug.cgi?id=29903

- https://lists.suse.com/pipermail/sle-security-updates/2022-January/010013.html

-

- https://lists.suse.com/pipermail/sle-security-updates/2022-February/010243.html

-

- https://ubuntu.com/security/notices/USN-5309-1

- https://www.cve.org/CVERecord?id=CVE-2022-0135

- https://www.cve.org/CVERecord?id=CVE-2022-0175

Resolution

SRPMS

- 8/core/virglrenderer-0.8.2-1.20200212git7d204f39.1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 01 Nov 2022
URL: https://advisories.mageia.org/MGASA-2022-0401.html
Type: security
CVE: CVE-2022-0135, CVE-2022-0175

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here