
CVE-2017-5580 – Gentoo Linux Security Advisory 201707-06
https://notcve.org/view.php?id=CVE-2017-5580
15 Mar 2017 — The parse_instruction function in gallium/auxiliary/tgsi/tgsi_text.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and process crash) via a crafted texture instruction. La función parse_instruction en gallium/auxiliar/tgsi/tgsi_text.c en virglrenderer en versiones anteriores a 0.6.0 permite a usuarios locales del SO invitado provocar una denegación de servicio (acceso al array fuera de límites y caída del proceso) a través de una instrucci... • http://www.openwall.com/lists/oss-security/2017/01/24/5 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-5993 – Gentoo Linux Security Advisory 201707-06
https://notcve.org/view.php?id=CVE-2017-5993
15 Mar 2017 — Memory leak in the vrend_renderer_init_blit_ctx function in vrend_blitter.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRGL_CCMD_BLIT commands. Pérdida de memoria en la función vrend_renderer_init_blit_ctx en vrend_blitter.c en virglrenderer en versiones anteriores a 0.6.0 permite a usuarios locales de SO invitado provocar una denegación de servicio (consumo de memoria del host) a través de un gran número de comando... • http://www.openwall.com/lists/oss-security/2017/02/15/7 • CWE-772: Missing Release of Resource after Effective Lifetime •

CVE-2017-5994 – Gentoo Linux Security Advisory 201707-06
https://notcve.org/view.php?id=CVE-2017-5994
15 Mar 2017 — Heap-based buffer overflow in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and crash) via the num_elements parameter. Desbordamiento de búfer basado en memoria dinámica en la función vrend_create_vertex_elements_state en vrend_renderer.c en virglrenderer en versiones anteriores a 0.6.0 permite a usuarios locales del SO invitado provocar una denegación de servicio (acceso ... • http://www.openwall.com/lists/oss-security/2017/02/15/8 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-6209 – Gentoo Linux Security Advisory 201707-06
https://notcve.org/view.php?id=CVE-2017-6209
15 Mar 2017 — Stack-based buffer overflow in the parse_identifier function in tgsi_text.c in the TGSI auxiliary module in the Gallium driver in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors related to parsing properties. Desbordamiento de búfer basado en pila en la función parse_identifier en tgsi_text.c en el módulo auxiliar TGSI en el controlador Gallium en virglrenderer en versiones anteriores a 0.6.0 permite a usuari... • http://www.openwall.com/lists/oss-security/2017/02/23/20 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-6210 – Gentoo Linux Security Advisory 201707-06
https://notcve.org/view.php?id=CVE-2017-6210
15 Mar 2017 — The vrend_decode_reset function in vrend_decode.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (NULL pointer dereference and QEMU process crash) by destroying context 0 (zero). La función vrend_decode_reset en vrend_decode.c en virglrenderer en versiones anteriores a 0.6.0 permite a usuarios locales del SO invitado provocar una denegación de servicio (referencia a puntero NULL y caída del proceso QEMU) destruyendo el contexto 0 (cero). Multiple vulnerabilities have ... • http://www.openwall.com/lists/oss-security/2017/02/23/21 • CWE-476: NULL Pointer Dereference •

CVE-2017-6317 – Gentoo Linux Security Advisory 201707-06
https://notcve.org/view.php?id=CVE-2017-6317
15 Mar 2017 — Memory leak in the add_shader_program function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) via vectors involving the sprog variable. Pérdida de memoria en la función add_shader_program en vrend_renderer.c en virglrenderer en versiones anteriores a 0.6.0 permite a usuarios locales del SO invitado provocar una denegación de servicio (consumo de memoria del host) a través de vectores que implican la variable sprog. Multipl... • http://www.openwall.com/lists/oss-security/2017/02/24/5 • CWE-772: Missing Release of Resource after Effective Lifetime •

CVE-2017-6386 – Gentoo Linux Security Advisory 201707-06
https://notcve.org/view.php?id=CVE-2017-6386
15 Mar 2017 — Memory leak in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRGL_OBJECT_VERTEX_ELEMENTS commands. Pérdida de memoria en la función vrend_create_vertex_elements_state en vrend_renderer.c en virglrenderer permite a usuarios locales del SO invitado provocar una denegación de servicio (consumo de memoria del host) a través de un gran número de comandos VIRGL_OBJECT_VE... • http://www.openwall.com/lists/oss-security/2017/03/01/7 • CWE-772: Missing Release of Resource after Effective Lifetime •

CVE-2017-5957 – Gentoo Linux Security Advisory 201707-06
https://notcve.org/view.php?id=CVE-2017-5957
14 Mar 2017 — Stack-based buffer overflow in the vrend_decode_set_framebuffer_state function in vrend_decode.c in virglrenderer before 926b9b3460a48f6454d8bbe9e44313d86a65447f, as used in Quick Emulator (QEMU), allows a local guest users to cause a denial of service (application crash) via the "nr_cbufs" argument. Desbordamiento del búfer basado en pila en la función vrend_decode_set_framebuffer_state en vrend_decode.c en virglrenderer en versiones anteriores a 926b9b3460a48f6454d8bbe9e44313d86a65447f, como se utiliza en... • http://www.openwall.com/lists/oss-security/2017/02/13/3 • CWE-787: Out-of-bounds Write •

CVE-2017-6355 – Gentoo Linux Security Advisory 201707-06
https://notcve.org/view.php?id=CVE-2017-6355
10 Mar 2017 — Integer overflow in the vrend_create_shader function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (process crash) via crafted pkt_length and offlen values, which trigger an out-of-bounds access. Desbordamiento de entero en la función vrend_create_shader en vrend_renderer.c en virglrenderer en versiones anteriores a 0.6.0 permite permite a usuarios locales del SO invitado provocar una denegación de servicio (caída del proceso) a través de valores ... • http://www.openwall.com/lists/oss-security/2017/02/27/3 • CWE-190: Integer Overflow or Wraparound •