Back to bug 2133452
| Who | When | What | Removed | Added |
|---|---|---|---|---|
| Mauro Matteo Cascella | 2022-10-10 14:21:28 UTC | Doc Text | A NULL pointer dereference issue was found in the Linux kernel's vmwgfx driver in vmw_cmd_dx_define_query. Exploiting this bug would require an attacker to have access to either /dev/dri/card0 or /dev/dri/rendererD128 and be able to issue an ioctl() on the resulting file descriptor. Under certain circumstances a local unprivileged user could use this flaw to crash the system, causing a denial of service. | |
| Mauro Matteo Cascella | 2022-10-10 15:28:41 UTC | Depends On | 2133489, 2133486, 2133485, 2133488, 2133487 | |
| RaTasha Tillery-Smith | 2022-10-10 17:51:27 UTC | Doc Text | A NULL pointer dereference issue was found in the Linux kernel's vmwgfx driver in vmw_cmd_dx_define_query. Exploiting this bug would require an attacker to have access to either /dev/dri/card0 or /dev/dri/rendererD128 and be able to issue an ioctl() on the resulting file descriptor. Under certain circumstances a local unprivileged user could use this flaw to crash the system, causing a denial of service. | A NULL pointer dereference issue was found in the Linux kernel's vmwgfx driver in vmw_cmd_dx_define_query. This flaw allows a local, unprivileged attacker with access to either /dev/dri/card0 or /dev/dri/rendererD128, who can issue an ioctl() on the resulting file descriptor, to crash the system, causing a denial of service. |
| Niels De Graef | 2022-11-15 10:13:07 UTC | CC | kraxel, ndegraef | |
| Flags | needinfo?(kraxel) | |||
| Mauro Matteo Cascella | 2022-11-23 10:16:13 UTC | Summary | CVE-2022-38096 kernel: vmxgfx: NULL pointer dereference in vmw_cmd_dx_define_query | CVE-2022-38096 kernel: vmwgfx: NULL pointer dereference in vmw_cmd_dx_define_query |
| Mauro Matteo Cascella | 2022-11-23 10:18:04 UTC | Flags | needinfo?(kraxel) | |
| Red Hat Bugzilla | 2022-12-31 23:35:06 UTC | CC | fhrbata | |
| Red Hat Bugzilla | 2023-04-01 08:40:23 UTC | CC | dhoward | |
| Red Hat Bugzilla | 2023-07-07 08:32:12 UTC | Assignee | security-response-team | nobody |
Back to bug 2133452