Out-of-bounds write in virglrenderer - CVE-2022-0135
Published: July 15, 2022
virglrenderer
virgl
Description
The vulnerability allows a local user to execute arbitrary code on the system.
The vulnerability exists due to a boundary error when processing untrusted input in the VirGL virtual OpenGL renderer. A local user can pass a specially crafted virgil resource and then issue a VIRTGPU_EXECBUFFER ioctl, leading to a denial of service or possible code execution.