CVE-2022-36280: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.8% chance of exploitation in the next 30 days.

An out-of-bounds(OOB) memory access vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_kms.c in GPU component in the Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).

Affected products

  • Debian Debian Linux: version 11.0 only
  • Linux Linux Kernel: from 3.2, up to and including 5.13.0-52

Published 2022-09-09. Last modified 2026-06-17.