First published: Thu Jan 06 2022(Updated: )
An out-of-bound write was found in virglrenderer in src/vrend_renderer.c:read_transfer_data().
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Freedesktop Virglrenderer | >=0.8.1<0.10.0 | |
Red Hat Enterprise Linux | =8.0 | |
Debian Debian Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0135 is an out-of-bounds write vulnerability in the VirGL virtual OpenGL renderer (virglrenderer) that can result in a denial of service or possible code execution.
CVE-2022-0135 affects Virglrenderer Project Virglrenderer versions between 0.8.1 and 0.10.0.
CVE-2022-0135 affects Redhat Enterprise Linux 8.0.
CVE-2022-0135 affects Debian Debian Linux 10.0.
CVE-2022-0135 has a severity level of 7.8 (High).
To fix CVE-2022-0135, it is recommended to update Virglrenderer Project Virglrenderer to a version beyond 0.10.0, Redhat Enterprise Linux 8 to a version that includes the fix, or Debian Debian Linux 10 to a version that includes the fix.