First published: Fri Sep 09 2022(Updated: )
A use-after-free vulnerability was found in the Linux kernel's vmwgfx driver in vmw_cmd_res_check. Systems making use of the vmwgfx driver are potentially affected by this flaw. Exploiting the bug would require an attacker to have access to either /dev/dri/card0 or /dev/dri/rendererD128 and be able to issue an ioctl() on the resulting file descriptor. Under certain circumstances a local unprivileged user could use this flaw to crash the system, causing a denial of service. Reference: <a href="https://bugzilla.openanolis.cn/show_bug.cgi?id=2074">https://bugzilla.openanolis.cn/show_bug.cgi?id=2074</a>
Credit: security@openanolis.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Governance - Identity Manager | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager | <=ISVG 10.0.2 | |
Linux kernel | >=4.20<6.1.7 | |
Linux kernel | =6.2-rc1 | |
Linux kernel | =6.2-rc2 | |
Linux kernel | =6.2-rc3 | |
Linux kernel | =6.2-rc4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38457 is classified as a use-after-free vulnerability which can lead to potential system exploitation.
To fix CVE-2022-38457, you should upgrade to a patched version of the Linux kernel or the affected IBM Security Verify Governance software components.
CVE-2022-38457 affects systems utilizing the Linux kernel with vmwgfx driver and also IBM Security Verify Governance components up to version 10.0.2.
An attacker exploiting CVE-2022-38457 could potentially execute arbitrary code with elevated privileges on the affected system.
CVE-2022-38457 affects Linux kernel versions between 4.20 and 6.1.7, as well as specific release candidates of version 6.2.