A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.
2022-08-26T18:15:08.660
2024-11-21T06:38:04.567
Modified
CVSSv3.1: 5.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | virglrenderer_project | virglrenderer | 0.9.0 | Yes |
Application | virglrenderer_project | virglrenderer | 0.9.1 | Yes |
Operating System | redhat | enterprise_linux | 8.0 | Yes |