REDHAT-BUG-1420246: Null Pointer Dereference
Virgil 3d project, used by Quick Emulator(Qemu) to implement 3D GPU support for the virtio GPU, is vulnerable to a null pointer dereference issue. It could occur when a guest invokes a virgl 'VIRGLCCMDCLEAR' command.
A guest user/process could use this flaw to crash Qemu process resulting in DoS.
Upstream patch: --------------- -> https://cgit.freedesktop.org/virglrenderer/commit/?id=48f67f60967f963b698ec8df57ec6912a43d6282
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/02/08/5
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1420246?
The vulnerability REDHAT-BUG-1420246 has a high severity as it can lead to a denial of service (DoS) by crashing the QEMU process.
How does the vulnerability REDHAT-BUG-1420246 occur?
The REDHAT-BUG-1420246 vulnerability occurs when a guest invokes the virgl 'VIRGL_CCMD_CLEAR' command, leading to a null pointer dereference.
Which software is affected by REDHAT-BUG-1420246?
The software affected by REDHAT-BUG-1420246 includes FreeDesktop Virglrenderer and QEMU.
How can I mitigate the risks associated with REDHAT-BUG-1420246?
To mitigate the risks of REDHAT-BUG-1420246, it is recommended to update to the patched versions of Virglrenderer and QEMU as provided by the vendors.
Is there any workaround for REDHAT-BUG-1420246?
As of now, the best practice is to avoid using the specific virgl 'VIRGL_CCMD_CLEAR' command until an official patch is applied for REDHAT-BUG-1420246.