CVE-2022-38096

Updated: 2024-11-24 04:33:50.036566

Description:

A NULL pointer dereference vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 5.5 MEDIUM Released CLSA-2025:1743193221 2024-09-02 17:36:35
CentOS 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2024-05-10 14:19:09
CentOS 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2024-05-10 14:19:09
CentOS 8.4 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2024-06-24 11:22:29
CentOS 8.5 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2024-06-24 11:22:29
CentOS Stream 8 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2024-05-10 14:19:09
CloudLinux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2024-05-10 14:19:09
Oracle Linux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2024-05-10 17:19:34
Ubuntu 18.04 ELS linux 4.15.0 5.5 MEDIUM Not Vulnerable 2024-12-24 22:07:37