CVE-2017-6355: Integer Overflow
Integer overflow in the vrendcreateshader function in vrendrenderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (process crash) via crafted pktlength and offlen values, which trigger an out-of-bounds access.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6355?
CVE-2017-6355 has a medium severity rating, as it can lead to denial of service through process crashes.
How do I fix CVE-2017-6355?
To mitigate CVE-2017-6355, upgrade to virglrenderer version 0.6.0 or later.
What causes CVE-2017-6355?
CVE-2017-6355 is caused by an integer overflow in the vrend_create_shader function, leading to out-of-bounds access.
Who is affected by CVE-2017-6355?
Local guest OS users running affected versions of virglrenderer prior to 0.6.0 are vulnerable to CVE-2017-6355.
What types of attacks can exploit CVE-2017-6355?
Exploitation of CVE-2017-6355 can lead to denial of service attacks, resulting in application crashes.