CVE-2022-36280: There is an out-of-bounds write vulnerability in vmwgfx driver
An out-of-bounds(OOB) memory access vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfxkms.c in GPU component in the Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).
Other sources
There is an out-of-bounds write vulnerability in vmwgfx driver
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36280?
CVE-2022-36280 is classified as a high severity vulnerability due to the potential for a local attacker to escalate privileges.
How do I fix CVE-2022-36280?
To mitigate CVE-2022-36280, update the Linux kernel to versions 5.10.223-1, 5.10.226-1, 6.1.119-1, 6.1.123-1, 6.12.11-1, or 6.12.12-1 if you are using Debian.
Who is affected by CVE-2022-36280?
CVE-2022-36280 affects users running vulnerable versions of the Linux kernel, specifically versions between 3.2 and 5.13.0-52, as well as specific Debian releases.
What is the nature of the vulnerability in CVE-2022-36280?
CVE-2022-36280 is an out-of-bounds memory access vulnerability found in the vmwgfx driver within the GPU component of the Linux kernel.
Can CVE-2022-36280 be exploited remotely?
CVE-2022-36280 requires local access to the machine, as it can only be exploited by an authenticated user.