Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
There is an UAF vulnerability in vmwgfx driver
Vulnerability Description
A use-after-free(UAF) vulnerability was found in function 'vmw_execbuf_tie_context' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in Linux kernel's vmwgfx driver with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H
Vulnerability Type
释放后使用
Vulnerability Title
Linux kernel 资源管理错误漏洞
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于其vmwgfx驱动程序的/gpu/vmxgfx/vmxgfx_execbuf.c组件中的“vmw_execbuf_tie_context”函数存在释放后重用,设备文件为“/dev/dri/renderD128(或Dxxx)”。该缺陷允许具有系统用户帐户的本地攻击者获得特权导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A