REDHAT-BUG-1426170: Null Pointer Dereference
Virgil 3d project, used by Quick Emulator(Qemu) to implement 3D GPU support for the virtio GPU, is vulnerable to a null pointer dereference flaw. It could occur when destroying renderer context zero(0) in 'vrenddecodereset'.
A guest user/process could use this flaw to crash the Qemu process instance resulting DoS.
Upstream patch: --------------- -> https://cgit.freedesktop.org/virglrenderer/commit/?id=0a5dff15912207b83018485f83e067474e818bab
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/02/23/21
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1426170?
The severity of REDHAT-BUG-1426170 is considered critical due to the potential for a denial-of-service attack.
How do I fix REDHAT-BUG-1426170?
To fix REDHAT-BUG-1426170, update to the latest version of the Freedesktop Virglrenderer and QEMU packages that include the security patch.
Who is affected by REDHAT-BUG-1426170?
Users of Freedesktop Virglrenderer and QEMU for virtualization are affected by REDHAT-BUG-1426170.
What is the impact of crashing the QEMU process due to REDHAT-BUG-1426170?
The crash of the QEMU process can lead to a denial-of-service situation for any virtual machines relying on it.
Is there a workaround for REDHAT-BUG-1426170?
Currently, there are no known effective workarounds for REDHAT-BUG-1426170 other than applying the security update.