ALT-PU-2017-1538-1
Package libvirglrenderer updated to version 0.6.0-alt1.S1 for branch sisyphus in task 182296.
Closed vulnerabilities
Modified: 2025-04-20
CVE-2016-10163
Memory leak in the vrend_renderer_context_create_internal function in vrend_decode.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) by repeatedly creating a decode context.
- http://www.openwall.com/lists/oss-security/2017/01/24/2
- http://www.openwall.com/lists/oss-security/2017/01/25/4
- http://www.securityfocus.com/bid/95784
- https://cgit.freedesktop.org/virglrenderer/commit/?id=747a293ff6055203e529f083896b823e22523fe7
- https://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.html
- https://security.gentoo.org/glsa/201707-06
- http://www.openwall.com/lists/oss-security/2017/01/24/2
- http://www.openwall.com/lists/oss-security/2017/01/25/4
- http://www.securityfocus.com/bid/95784
- https://cgit.freedesktop.org/virglrenderer/commit/?id=747a293ff6055203e529f083896b823e22523fe7
- https://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.html
- https://security.gentoo.org/glsa/201707-06
Modified: 2025-04-20
CVE-2016-10214
Memory leak in the virgl_resource_attach_backing function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_ATTACH_BACKING commands.
- http://www.openwall.com/lists/oss-security/2017/02/09/5
- http://www.securityfocus.com/bid/96181
- https://cgit.freedesktop.org/virglrenderer/commit/?id=40b0e7813325b08077b6f541b3989edb2d86d837
- https://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.html
- https://security.gentoo.org/glsa/201707-06
- http://www.openwall.com/lists/oss-security/2017/02/09/5
- http://www.securityfocus.com/bid/96181
- https://cgit.freedesktop.org/virglrenderer/commit/?id=40b0e7813325b08077b6f541b3989edb2d86d837
- https://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.html
- https://security.gentoo.org/glsa/201707-06
Modified: 2025-04-20
CVE-2017-5580
The parse_instruction function in gallium/auxiliary/tgsi/tgsi_text.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and process crash) via a crafted texture instruction.
- http://www.openwall.com/lists/oss-security/2017/01/24/5
- http://www.openwall.com/lists/oss-security/2017/01/25/5
- http://www.securityfocus.com/bid/95782
- https://cgit.freedesktop.org/virglrenderer/commit/src/gallium/auxiliary/tgsi/tgsi_text.c?id=28894a30a17a84529be102b21118e55d6c9f23fa
- https://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.html
- https://security.gentoo.org/glsa/201707-06
- http://www.openwall.com/lists/oss-security/2017/01/24/5
- http://www.openwall.com/lists/oss-security/2017/01/25/5
- http://www.securityfocus.com/bid/95782
- https://cgit.freedesktop.org/virglrenderer/commit/src/gallium/auxiliary/tgsi/tgsi_text.c?id=28894a30a17a84529be102b21118e55d6c9f23fa
- https://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.html
- https://security.gentoo.org/glsa/201707-06
Modified: 2025-04-20
CVE-2017-5937
The util_format_is_pure_uint function in vrend_renderer.c in Virgil 3d project (aka virglrenderer) 0.6.0 and earlier allows local guest OS users to cause a denial of service (NULL pointer dereference) via a crafted VIRGL_CCMD_CLEAR command.
- http://www.openwall.com/lists/oss-security/2017/02/09/4
- http://www.securityfocus.com/bid/96180
- https://bugzilla.redhat.com/show_bug.cgi?id=1420246
- https://cgit.freedesktop.org/virglrenderer/commit/?id=48f67f60967f963b698ec8df57ec6912a43d6282
- http://www.openwall.com/lists/oss-security/2017/02/09/4
- http://www.securityfocus.com/bid/96180
- https://bugzilla.redhat.com/show_bug.cgi?id=1420246
- https://cgit.freedesktop.org/virglrenderer/commit/?id=48f67f60967f963b698ec8df57ec6912a43d6282
Modified: 2025-04-20
CVE-2017-5956
The vrend_draw_vbo function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors involving vertext_buffer_index.
- http://www.openwall.com/lists/oss-security/2017/02/13/2
- http://www.securityfocus.com/bid/96187
- https://cgit.freedesktop.org/virglrenderer/commit/?id=a5ac49940c40ae415eac0cf912eac7070b4ba95d
- https://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.html
- https://security.gentoo.org/glsa/201707-06
- http://www.openwall.com/lists/oss-security/2017/02/13/2
- http://www.securityfocus.com/bid/96187
- https://cgit.freedesktop.org/virglrenderer/commit/?id=a5ac49940c40ae415eac0cf912eac7070b4ba95d
- https://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.html
- https://security.gentoo.org/glsa/201707-06
Modified: 2025-04-20
CVE-2017-5993
Memory leak in the vrend_renderer_init_blit_ctx function in vrend_blitter.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRGL_CCMD_BLIT commands.
- http://www.openwall.com/lists/oss-security/2017/02/15/7
- http://www.securityfocus.com/bid/96275
- https://bugzilla.redhat.com/show_bug.cgi?id=1422438
- https://cgit.freedesktop.org/virglrenderer/commit/?id=6eb13f7a2dcf391ec9e19b4c2a79e68305f63c22
- https://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.html
- https://security.gentoo.org/glsa/201707-06
- http://www.openwall.com/lists/oss-security/2017/02/15/7
- http://www.securityfocus.com/bid/96275
- https://bugzilla.redhat.com/show_bug.cgi?id=1422438
- https://cgit.freedesktop.org/virglrenderer/commit/?id=6eb13f7a2dcf391ec9e19b4c2a79e68305f63c22
- https://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.html
- https://security.gentoo.org/glsa/201707-06
Modified: 2025-04-20
CVE-2017-5994
Heap-based buffer overflow in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and crash) via the num_elements parameter.
- http://www.openwall.com/lists/oss-security/2017/02/15/8
- http://www.securityfocus.com/bid/96276
- https://bugzilla.redhat.com/show_bug.cgi?id=1422452
- https://cgit.freedesktop.org/virglrenderer/commit/?id=114688c526fe45f341d75ccd1d85473c3b08f7a7
- https://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.html
- https://security.gentoo.org/glsa/201707-06
- http://www.openwall.com/lists/oss-security/2017/02/15/8
- http://www.securityfocus.com/bid/96276
- https://bugzilla.redhat.com/show_bug.cgi?id=1422452
- https://cgit.freedesktop.org/virglrenderer/commit/?id=114688c526fe45f341d75ccd1d85473c3b08f7a7
- https://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.html
- https://security.gentoo.org/glsa/201707-06
Modified: 2025-04-20
CVE-2017-6209
Stack-based buffer overflow in the parse_identifier function in tgsi_text.c in the TGSI auxiliary module in the Gallium driver in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors related to parsing properties.
- http://www.openwall.com/lists/oss-security/2017/02/23/20
- http://www.securityfocus.com/bid/96437
- https://bugzilla.redhat.com/show_bug.cgi?id=1426149
- https://cgit.freedesktop.org/virglrenderer/commit/?id=e534b51ca3c3cd25f3990589932a9ed711c59b27
- https://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.html
- https://security.gentoo.org/glsa/201707-06
- http://www.openwall.com/lists/oss-security/2017/02/23/20
- http://www.securityfocus.com/bid/96437
- https://bugzilla.redhat.com/show_bug.cgi?id=1426149
- https://cgit.freedesktop.org/virglrenderer/commit/?id=e534b51ca3c3cd25f3990589932a9ed711c59b27
- https://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.html
- https://security.gentoo.org/glsa/201707-06
Modified: 2025-04-20
CVE-2017-6210
The vrend_decode_reset function in vrend_decode.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (NULL pointer dereference and QEMU process crash) by destroying context 0 (zero).
- http://www.openwall.com/lists/oss-security/2017/02/23/21
- http://www.securityfocus.com/bid/96439
- https://bugzilla.redhat.com/show_bug.cgi?id=1426170
- https://cgit.freedesktop.org/virglrenderer/commit/?id=0a5dff15912207b83018485f83e067474e818bab
- https://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.html
- https://security.gentoo.org/glsa/201707-06
- http://www.openwall.com/lists/oss-security/2017/02/23/21
- http://www.securityfocus.com/bid/96439
- https://bugzilla.redhat.com/show_bug.cgi?id=1426170
- https://cgit.freedesktop.org/virglrenderer/commit/?id=0a5dff15912207b83018485f83e067474e818bab
- https://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.html
- https://security.gentoo.org/glsa/201707-06
Modified: 2025-04-20
CVE-2017-6317
Memory leak in the add_shader_program function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) via vectors involving the sprog variable.
- http://www.openwall.com/lists/oss-security/2017/02/24/5
- http://www.securityfocus.com/bid/96450
- https://bugzilla.redhat.com/show_bug.cgi?id=1426756
- https://cgit.freedesktop.org/virglrenderer/commit/?id=a2f12a1b0f95b13b6f8dc3d05d7b74b4386394e4
- https://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.html
- https://security.gentoo.org/glsa/201707-06
- http://www.openwall.com/lists/oss-security/2017/02/24/5
- http://www.securityfocus.com/bid/96450
- https://bugzilla.redhat.com/show_bug.cgi?id=1426756
- https://cgit.freedesktop.org/virglrenderer/commit/?id=a2f12a1b0f95b13b6f8dc3d05d7b74b4386394e4
- https://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.html
- https://security.gentoo.org/glsa/201707-06