Name | CVE-2017-5994 |
Description | Heap-based buffer overflow in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and crash) via the num_elements parameter. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 858255 |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
virglrenderer (PTS) | buster | 0.7.0-2 | fixed |
| buster (security) | 0.7.0-2+deb10u1 | fixed |
| bullseye | 0.8.2-5+deb11u1 | fixed |
| bookworm | 0.10.4-1 | fixed |
| trixie, sid | 1.0.0-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|
virglrenderer | source | (unstable) | 0.6.0-1 | | | 858255 |
Notes
https://cgit.freedesktop.org/virglrenderer/commit/?id=114688c526fe45f341d75ccd1d85473c3b08f7a7 (0.6.0)
https://bugzilla.redhat.com/show_bug.cgi?id=1422452