First published: Fri Sep 09 2022(Updated: )
A use-after-free vulnerability was found in the Linux kernel's vmwgfx driver in vmw_execbuf_tie_context. Systems making use of the vmwgfx driver are potentially affected by this flaw. Exploiting the bug would require an attacker to have access to either /dev/dri/card0 or /dev/dri/rendererD128 and be able to issue an ioctl() on the resulting file descriptor. Under certain circumstances a local unprivileged user could use this flaw to crash the system, causing a denial of service. Reference: <a href="https://bugzilla.openanolis.cn/show_bug.cgi?id=2075">https://bugzilla.openanolis.cn/show_bug.cgi?id=2075</a>
Credit: security@openanolis.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | >=4.20<6.1.7 | |
Linux Kernel | =6.2-rc1 | |
Linux Kernel | =6.2-rc2 | |
Linux Kernel | =6.2-rc3 | |
Linux Kernel | =6.2-rc4 | |
IBM Security Verify Governance - Identity Manager | <=ISVG 10.0.2 | |
IBM Security Verify Governance - Identity Manager | <=ISVG 10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40133 is classified as a high severity vulnerability due to its potential impact and exploitability.
To fix CVE-2022-40133, update the affected Linux kernel versions to the latest patched release.
CVE-2022-40133 affects the IBM Security Verify Governance, Identity Manager software, its virtual appliance, and specific versions of the Linux kernel.
CVE-2022-40133 is a use-after-free vulnerability found in the vmwgfx driver of the Linux kernel.
Exploiting CVE-2022-40133 could allow an attacker with access to certain device files to potentially execute arbitrary code.