REDHAT-BUG-1426149: Medium severity libvirglrenderer vulnerability
Virgil 3d project, used by Quick Emulator(Qemu) to implement 3D GPU support for the virtio GPU, is vulnerable to an OOB array access issue. It could occur when parsing properties in parseidentifier().
A guest user/process could use this flaw to crash the Qemu process instance resulting DoS.
Upstream patch: --------------- -> https://cgit.freedesktop.org/virglrenderer/commit/?id=e534b51ca3c3cd25f3990589932a9ed711c59b27
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/02/23/20
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1426149?
The severity of REDHAT-BUG-1426149 is considered high due to the potential for a denial of service attack.
How do I fix REDHAT-BUG-1426149?
To fix REDHAT-BUG-1426149, update the affected QEMU and Virglrenderer packages to the latest versions that include the patch for this vulnerability.
What systems are affected by REDHAT-BUG-1426149?
REDHAT-BUG-1426149 affects systems that run QEMU utilizing the Virglrenderer project for 3D GPU support.
What type of vulnerability is REDHAT-BUG-1426149?
REDHAT-BUG-1426149 is an out-of-bounds (OOB) array access vulnerability.
Can a guest user exploit REDHAT-BUG-1426149?
Yes, a guest user or process can exploit REDHAT-BUG-1426149 to crash the QEMU process, leading to denial of service.