REDHAT-BUG-1765577: Buffer Overflow
A heap-based buffer overflow in the vrendrenderertransferwriteiov function in vrendrenderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service, or QEMU guest-to-host escape and code execution, via VIRGLCCMDRESOURCEINLINEWRITE commands.
Upstream Issue:
https://gitlab.freedesktop.org/virgl/virglrenderer/mergerequests/314/diffs?commitid=9c280a28651507e6ef87b17b90d47b6af3a4ab7d
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1765577?
The severity of REDHAT-BUG-1765577 is critical due to the potential for denial of service and guest-to-host escape leading to code execution.
How do I fix REDHAT-BUG-1765577?
To fix REDHAT-BUG-1765577, upgrade to virglrenderer version above 0.8.0.
Which software is affected by REDHAT-BUG-1765577?
Freedesktop virglrenderer versions up to and including 0.8.0 are affected by REDHAT-BUG-1765577.
What types of attacks can REDHAT-BUG-1765577 enable?
REDHAT-BUG-1765577 can enable denial of service attacks and potential code execution via guest-to-host escape.
Is there an upstream issue related to REDHAT-BUG-1765577?
Yes, the upstream issue for REDHAT-BUG-1765577 has been tracked in the Freedesktop project repositories.