First published: Fri Oct 25 2019(Updated: )
A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via malformed commands.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Freedesktop Virglrenderer | <=0.8.0 | |
openSUSE | =15.1 | |
Debian Debian Linux | =10.0 |
https://gitlab.freedesktop.org/virgl/virglrenderer/commit/0d9a2c88dc3a70023541b3260b9f00c982abda16
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-18388 is medium with a CVSS score of 5.5.
CVE-2019-18388 affects Virglrenderer version 0.8.0 and openSUSE Leap 15.1, as well as Debian Linux 10.0.
CVE-2019-18388 can be exploited by guest OS users sending malformed commands, leading to a NULL pointer dereference and denial of service.
You can find more information about CVE-2019-18388 at the following references: [1] [2] [3]
The Common Weakness Enumeration (CWE) ID for CVE-2019-18388 is 476.