Virgil 3d project, used by Quick Emulator(Qemu) to implement 3D GPU support for the virtio GPU, is vulnerable to an OOB array access issue. It could occur when creating vertex elements array in vrend_create_vertex_elements_state(). A guest user/process could use this flaw to crash the Qemu process instance resulting DoS. Upstream patch: --------------- -> https://cgit.freedesktop.org/virglrenderer/commit/?id=114688c526fe45f341d75ccd1d85473c3b08f7a7 Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/02/15/8
Acknowledgments: Name: Li Qiang (360.cn Inc.)
Created virglrenderer tracking bugs for this issue: Affects: fedora-all [bug 1422453]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.