CVE-2017-5956: Medium severity Virglrenderer Project Virglrenderer vulnerability
Published Mar 20, 2017
·Updated
The vrenddrawvbo function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors involving vertextbufferindex.
Affected Software
1 affected component
Virglrenderer Project Virglrenderer<=0.5.0
Remediation
Patch Available
Event History
Mar 20, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5956?
CVE-2017-5956 has a medium severity level as it can lead to a denial of service.
2
How do I fix CVE-2017-5956?
To fix CVE-2017-5956, upgrade to virglrenderer version 0.6.0 or later.
3
Who is affected by CVE-2017-5956?
CVE-2017-5956 affects local guest OS users running virglrenderer versions prior to 0.6.0.
4
What type of vulnerability is CVE-2017-5956?
CVE-2017-5956 is a denial of service vulnerability caused by an out-of-bounds array access in the vrend_draw_vbo function.
5
What could happen if I don't address CVE-2017-5956?
If CVE-2017-5956 is not addressed, it can result in the QEMU process crashing, leading to service interruptions.