{
  "threat_severity" : "Moderate",
  "public_date" : "2021-12-14T00:00:00Z",
  "bugzilla" : {
    "description" : "virglrenderer: memory initialization issue in vrend_resource_alloc_buffer() can lead to info leak",
    "id" : "2039003",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2039003"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
    "status" : "draft"
  },
  "cwe" : "CWE-909",
  "details" : [ "A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.", "A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure." ],
  "statement" : "This flaw does not affect Red Hat Enterprise Linux as `virglrenderer` is not shipped in RHEL. Support for VirGL was enabled as a Technology Preview in Red Hat Enterprise Linux Advanced Virtualization 8.2 and later disabled in Red Hat Enterprise Linux Advanced Virtualization 8.3. For more information on the Technology Preview support scope, please refer to https://access.redhat.com/support/offerings/techpreview.",
  "acknowledgement" : "Red Hat would like to thank Jun Yao for reporting this issue.",
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 8 Advanced Virtualization",
    "fix_state" : "Affected",
    "package_name" : "virt:8.2/virglrenderer",
    "cpe" : "cpe:/a:redhat:advanced_virtualization:8::el8"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2022-0175\nhttps://nvd.nist.gov/vuln/detail/CVE-2022-0175" ],
  "name" : "CVE-2022-0175",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}