REDHAT-BUG-1422452: Medium severity libvirglrenderer vulnerability
Virgil 3d project, used by Quick Emulator(Qemu) to implement 3D GPU support for the virtio GPU, is vulnerable to an OOB array access issue. It could occur when creating vertex elements array in vrendcreatevertexelementsstate().
A guest user/process could use this flaw to crash the Qemu process instance resulting DoS.
Upstream patch: --------------- -> https://cgit.freedesktop.org/virglrenderer/commit/?id=114688c526fe45f341d75ccd1d85473c3b08f7a7
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/02/15/8
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1422452?
REDHAT-BUG-1422452 is classified as a high severity vulnerability due to the potential for crashing the Qemu process.
How do I fix REDHAT-BUG-1422452?
To fix REDHAT-BUG-1422452, update to the latest version of Qemu or apply the relevant patches provided by the developers.
Which software is affected by REDHAT-BUG-1422452?
The affected software includes the Freedesktop Virglrenderer and Open Source Qemu.
What strategies can be used to mitigate REDHAT-BUG-1422452?
To mitigate REDHAT-BUG-1422452, consider limiting the privileges of guest users and ensuring that your Qemu environment is correctly configured.
What type of vulnerability is REDHAT-BUG-1422452?
REDHAT-BUG-1422452 is an out-of-bounds (OOB) array access vulnerability that can be exploited to crash the Qemu process.