OESA-2021-1427
Dashboard / Vulnerabilities / OESA-2021-1427
OESA-2021-1427
Summary: virglrenderer security update
Details: The virgil3d rendering library is a library used by qemu to implement 3D GPU support for the virtio GPU. Security Fix(es): An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_BLIT commands.(CVE-2019-18390) A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via malformed commands.(CVE-2019-18388) A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.(CVE-2019-18391) A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service, or QEMU guest-to-host escape and code execution, via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.(CVE-2019-18389)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1427, https://nvd.nist.gov/vuln/detail/CVE-2019-18390, https://nvd.nist.gov/vuln/detail/CVE-2019-18388, https://nvd.nist.gov/vuln/detail/CVE-2019-18391, https://nvd.nist.gov/vuln/detail/CVE-2019-18389
Affected packages
Package
Name: virglrenderer
Purl: pkg:rpm/openEuler/virglrenderer&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
