Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-5956

Опубликовано: 20 мар. 2017
Источник: debian
EPSS Низкий

Описание

The vrend_draw_vbo function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors involving vertext_buffer_index.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
virglrendererfixed0.6.0-1package

Примечания

  • https://cgit.freedesktop.org/virglrenderer/commit/?id=a5ac49940c40ae415eac0cf912eac7070b4ba95d (0.6.0)

  • https://bugzilla.redhat.com/show_bug.cgi?id=1421073

  • The original fix opens a memory leak: https://www.openwall.com/lists/oss-security/2017/02/24/2

  • Additional patch required: https://bugzilla.suse.com/attachment.cgi?id=715395

EPSS

Процентиль: 25%
0.00085
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

The vrend_draw_vbo function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors involving vertext_buffer_index.

CVSS3: 5.5
nvd
почти 9 лет назад

The vrend_draw_vbo function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors involving vertext_buffer_index.

CVSS3: 5.5
github
больше 3 лет назад

The vrend_draw_vbo function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors involving vertext_buffer_index.

suse-cvrf
почти 9 лет назад

Security update for virglrenderer

suse-cvrf
почти 9 лет назад

Security update for virglrenderer

EPSS

Процентиль: 25%
0.00085
Низкий