CVE-2022-3707 is a double-free memory flaw in the Linux kernel's Intel GVT-g graphics driver, affecting various Linux distributions including Red Hat Enterprise Linux. This vulnerability can be triggered by a local user, leading to a system crash due to VGA card resource overload. With a CVSS score of 5.5 (Medium), it requires local access and low attack complexity to achieve high availability impact. Currently, there is no known public exploit code, Metasploit modules, or Nuclei templates, and it lacks significant community discussion or media coverage, indicating a low exploitation risk at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.1CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.1CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.1:-:*:*:*:*:*:* | ||
6.1CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.1:rc1:*:*:*:*:*:* | ||
6.1CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.1:rc2:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
A double-free memory flaw was found in the Linux kernel. The Intel GVT-g graphics driver triggers VGA card system resource overload causing a fail in the intel_gvt_dma_map_guest_page function. This issue could allow a local user to crash the system.
Mar 14, 2023kernel: Double-free in split_2MB_gtt_entry when function intel_gvt_dma_map_guest_page failed
Oct 7, 2022