Out-of-bounds read in some Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentially enable information disclosure via local access.
[
{
"id": "CVE-2023-22338-25ace10a",
"signature_version": "v1",
"digest": {
"function_hash": "58968368041516948208123275748297229214",
"length": 3429.0
},
"deprecated": false,
"source": "https://github.com/oneapi-src/onevpl-intel-gpu/commit/e74a3ce334b52577081e14a1656f74ccb3f1ef69",
"signature_type": "Function",
"target": {
"file": "_studio/shared/src/mfx_umc_alloc_wrapper.cpp",
"function": "mfx_UMC_FrameAllocator::SetCurrentMFXSurface"
}
},
{
"id": "CVE-2023-22338-722bea7a",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"127815607185161824860268287546718453980",
"320115815778025591393491370225689512979",
"315784990419394202010625698347752066775",
"226153859941423935464128588724854864132",
"63882282617262175192406149549634155181"
]
},
"deprecated": false,
"source": "https://github.com/oneapi-src/onevpl-intel-gpu/commit/e74a3ce334b52577081e14a1656f74ccb3f1ef69",
"signature_type": "Line",
"target": {
"file": "_studio/shared/include/libmfx_allocator.h"
}
},
{
"id": "CVE-2023-22338-960306a4",
"signature_version": "v1",
"digest": {
"function_hash": "166194482671779221226986818525971932913",
"length": 169.0
},
"deprecated": false,
"source": "https://github.com/oneapi-src/onevpl-intel-gpu/commit/e74a3ce334b52577081e14a1656f74ccb3f1ef69",
"signature_type": "Function",
"target": {
"file": "_studio/shared/src/mfx_umc_alloc_wrapper.cpp",
"function": "mfx_UMC_FrameAllocator::SetExternalFramesResponse"
}
},
{
"id": "CVE-2023-22338-e760bae3",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"312039055150589112433810206245891106824",
"320238461323602488822557772577769763670",
"281548539844001982204582923362471732893",
"299102011061710755517849413895160034721",
"272378930111953665384239869673881446970",
"80390843166064787806488337265028646338",
"4793327656027705016188399618560158622",
"101893365487331466771595779946331630272",
"61737317376152588170580725589360271480",
"323400590524608318649401392112789176879",
"261420573773080343049606690066634241054",
"38035435321234733549026979257608523660",
"4966413660044547460187952293327576036",
"146288751282928618348218941670333010870",
"150424730437380912621711475676886632662",
"75407180318704451699303769443305508093",
"332010472085322347507087666856049141212",
"80390843166064787806488337265028646338",
"308927958202073851913638076810067896685",
"51469739986747637697535844126917473040",
"18467009235161361035017670003927240090",
"25333513848265915865036510419078575285",
"237226826838613570956912097638078780427",
"105605137058827540951530958664419267910",
"303823492711345530028796990053148974681",
"251592243562671956060082369307712597300",
"23394590075771910777315139314438061302",
"255389278390388517230700109489640307201",
"267078642952274299384019515691713970288",
"148861462883186538828775868964476682967",
"313749585045524531825877682474861955682",
"127066892490578360446488640645209527264"
]
},
"deprecated": false,
"source": "https://github.com/oneapi-src/onevpl-intel-gpu/commit/e74a3ce334b52577081e14a1656f74ccb3f1ef69",
"signature_type": "Line",
"target": {
"file": "_studio/shared/src/mfx_umc_alloc_wrapper.cpp"
}
},
{
"id": "CVE-2023-22338-ead899c8",
"signature_version": "v1",
"digest": {
"function_hash": "25905277892014686129021884217089663925",
"length": 4732.0
},
"deprecated": false,
"source": "https://github.com/oneapi-src/onevpl-intel-gpu/commit/e74a3ce334b52577081e14a1656f74ccb3f1ef69",
"signature_type": "Function",
"target": {
"file": "_studio/shared/src/mfx_umc_alloc_wrapper.cpp",
"function": "SurfaceSource::SurfaceSource"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-22338.json"