A heap-based buffer overflow in the vrendrenderertransferwriteiov function in vrendrenderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGLCCMDRESOURCEINLINEWRITE commands.
Upstream Issue:
https://gitlab.freedesktop.org/virgl/virglrenderer/mergerequests/314/diffs?commitid=8c9cfb4e425542e96f0717189fe4658555baaf08
A heap-based buffer overflow in the vrendrenderertransferwriteiov function in vrendrenderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service, or QEMU guest-to-host escape and code execution, via VIRGLCCMDRESOURCEINLINEWRITE commands.
Upstream Issue:
https://gitlab.freedesktop.org/virgl/virglrenderer/mergerequests/314/diffs?commitid=9c280a28651507e6ef87b17b90d47b6af3a4ab7d
Virgil 3d project, used by Quick Emulator(Qemu) to implement 3D GPU support for the virtio GPU, is vulnerable to an OOB array access issue. It could occur when creating vertex elements array in vrendcreatevertexelementsstate().
A guest user/process could use this flaw to crash the Qemu process instance resulting DoS.
Upstream patch: --------------- -> https://cgit.freedesktop.org/virglrenderer/commit/?id=114688c526fe45f341d75ccd1d85473c3b08f7a7
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/02/15/8
Virgil 3d project, used by Quick Emulator(Qemu) to implement 3D GPU support for the virtio GPU, is vulnerable to an stack buffer overflow issue. It could occur when in vrenddecodesetframebufferstate.
A guest user/process could use this flaw to crash the Qemu process instance resulting DoS.
Upstream patch: --------------- -> https://cgit.freedesktop.org/virglrenderer/commit/?id=926b9b3460a48f6454d8bbe9e44313d86a65447f
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/02/13/3
Virgil 3d project, used by Quick Emulator(Qemu) to implement 3D GPU support for the virtio GPU, is vulnerable to an OOB array access issue. It could occur when parsing properties in parseidentifier().
A guest user/process could use this flaw to crash the Qemu process instance resulting DoS.
Upstream patch: --------------- -> https://cgit.freedesktop.org/virglrenderer/commit/?id=e534b51ca3c3cd25f3990589932a9ed711c59b27
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/02/23/20
The virgl forgets to initialize the memory pointed by the res->ptr when it creates resource. And the memory can be mapped to the guest kernel when the VIRTIOGPUCMDRESOURCEATTACHBACKING is issued. However, the guest userspace can read the data in the unintialized host memory by mmaping it from the guest kernel.
Upstream fix:
https://gitlab.freedesktop.org/virgl/virglrenderer/-/commit/b05bb61f454eeb8a85164c8a31510aeb9d79129c
Virgil 3d project, used by Quick Emulator(Qemu) to implement 3D GPU support for the virtio GPU, is vulnerable to a null pointer dereference issue. It could occur when a guest invokes a virgl 'VIRGLCCMDCLEAR' command.
A guest user/process could use this flaw to crash Qemu process resulting in DoS.
Upstream patch: --------------- -> https://cgit.freedesktop.org/virglrenderer/commit/?id=48f67f60967f963b698ec8df57ec6912a43d6282
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/02/08/5
Virgil 3d project, used by Quick Emulator(Qemu) to implement 3D GPU support for the virtio GPU, is vulnerable to memory leakage issue. It could occur when a guest tries to initialise blitter context via 'VIRGLCCMDBLIT' command.
A guest user/process could use this flaw to leak host memory resulting in DoS.
Upstream patch: --------------- -> https://cgit.freedesktop.org/virglrenderer/commit/?id=6eb13f7a2dcf391ec9e19b4c2a79e68305f63c22
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/02/15/7
Virgil 3d project, used by Quick Emulator(Qemu) to implement 3D GPU support for the virtio GPU, is vulnerable to a null pointer dereference flaw. It could occur when destroying renderer context zero(0) in 'vrenddecodereset'.
A guest user/process could use this flaw to crash the Qemu process instance resulting DoS.
Upstream patch: --------------- -> https://cgit.freedesktop.org/virglrenderer/commit/?id=0a5dff15912207b83018485f83e067474e818bab
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/02/23/21
Virgil 3d project, used by Quick Emulator(Qemu) to implement 3D GPU support for the virtio GPU, is vulnerable to a memory leakageissue. It could occur while in addshaderprogram().
A guest user/process could use this flaw to leak host memory resulting in DoS.
Upstream patch: --------------- -> https://cgit.freedesktop.org/virglrenderer/commit/?id=a2f12a1b0f95b13b6f8dc3d05d7b74b4386394e4
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/02/24/5
An out-of-bounds read in the vrendblitneedswizzle function in vrendrenderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGLCCMDBLIT commands.
Upstream Issue:
https://gitlab.freedesktop.org/virgl/virglrenderer/mergerequests/314/diffs?commitid=d2cdbcf6a8f2317f250fd54f08aa35dde2fa3e30#3cd772559e0d73afa136d6818023cfd0c4c8ecc00151
A NULL pointer dereference in vrendrenderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via malformed commands.
Upstream Issue:
https://gitlab.freedesktop.org/virgl/virglrenderer/mergerequests/314/diffs?commitid=d2cdbcf6a8f2317f250fd54f08aa35dde2fa3e30#3cd772559e0d73afa136d6818023cfd0c4c8ecc00589