First published: Fri Sep 09 2022(Updated: )
An out-of-bounds(OOB) memory access vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_kms.c in GPU component in the Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).
Credit: security@openanolis.org security@openanolis.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | >=3.2<=5.13.0-52 | |
Debian Debian Linux | =11.0 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.119-1 6.12.11-1 6.12.12-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36280 is classified as a high severity vulnerability due to the potential for a local attacker to escalate privileges.
To mitigate CVE-2022-36280, update the Linux kernel to versions 5.10.223-1, 5.10.226-1, 6.1.119-1, 6.1.123-1, 6.12.11-1, or 6.12.12-1 if you are using Debian.
CVE-2022-36280 affects users running vulnerable versions of the Linux kernel, specifically versions between 3.2 and 5.13.0-52, as well as specific Debian releases.
CVE-2022-36280 is an out-of-bounds memory access vulnerability found in the vmwgfx driver within the GPU component of the Linux kernel.
CVE-2022-36280 requires local access to the machine, as it can only be exploited by an authenticated user.