Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 726048 - [stefantalpalaru overlay] app-emulation/vmware-workstation-15.5.2 : VMSA-2020-0011 / CVE-2020-3958
Summary: [stefantalpalaru overlay] app-emulation/vmware-workstation-15.5.2 : VMSA-2020...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Ștefan Talpalaru
URL: https://www.vmware.com/security/advis...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-05-29 08:50 UTC by Manfred Knick
Modified: 2020-11-21 16:24 UTC (History)
5 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Manfred Knick 2020-05-29 08:50:08 UTC
3b. Denial-of-service vulnerability in Shader functionality (CVE-2020-3958)

Description:

VMware ESXi, Workstation and Fusion contain a denial-of-service vulnerability in the shader functionality. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.0.


Reproducible: Always




WORKAROUND:   Disable 3D acceleration
              [ https://kb.vmware.com/s/article/59146 ]

REFERENCE:
Bug 713068 - [stefantalpalaru overlay]
             app-emulation/vmware-workstation-15.5.2 version bump
Comment 1 Manfred Knick 2020-05-29 09:03:07 UTC
Known Attack Vectors:

Exploitation of this issue require an attacker to have access to a virtual machine with 3D graphics enabled. It is not enabled by default on ESXi and is enabled by default on Workstation and Fusion.

Successful exploitation of this issue may allow attackers with non-administrative access to a virtual machine to crash the virtual machine's vmx process leading to a denial of service condition.


==> My personal view on this:

If you can be sure to be the very only one with access to your VM,
you can still enjoy 3D.

If you have opened access to others,
  especially to *remote* users,
    especially providing an external service,
this CVE strongly suggests to disable 3D in the VM's System Settings immediately.
Comment 2 Manfred Knick 2020-11-21 12:44:36 UTC
Please, neware the nearing EOL of -15:
    https://bugs.gentoo.org/742647#c6
Comment 3 Ștefan Talpalaru 2020-11-21 16:24:19 UTC
No longer affecting us.