Stack-based buffer overflow in the vrend_decode_set_framebuffer_state function in vrend_decode.c in virglrenderer before 926b9b3460a48f6454d8bbe9e44313d86a65447f, as used in Quick Emulator (QEMU), allows a local guest users to cause a denial of service (application crash) via the "nr_cbufs" argument.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.openwall.com/lists/oss-security/2017/02/13/3 | Mailing List Patch Third Party Advisory | 
| http://www.securityfocus.com/bid/96215 | Third Party Advisory VDB Entry | 
| https://bugzilla.redhat.com/show_bug.cgi?id=1421126 | Issue Tracking Patch Third Party Advisory VDB Entry | 
| https://cgit.freedesktop.org/virglrenderer/commit/?id=926b9b3460a48f6454d8bbe9e44313d86a65447f | Patch Third Party Advisory | 
| https://security.gentoo.org/glsa/201707-06 | Third Party Advisory | 
| http://www.openwall.com/lists/oss-security/2017/02/13/3 | Mailing List Patch Third Party Advisory | 
| http://www.securityfocus.com/bid/96215 | Third Party Advisory VDB Entry | 
| https://bugzilla.redhat.com/show_bug.cgi?id=1421126 | Issue Tracking Patch Third Party Advisory VDB Entry | 
| https://cgit.freedesktop.org/virglrenderer/commit/?id=926b9b3460a48f6454d8bbe9e44313d86a65447f | Patch Third Party Advisory | 
| https://security.gentoo.org/glsa/201707-06 | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    No history.
Information
                Published : 2017-03-14 14:59
Updated : 2025-04-20 01:37
NVD link : CVE-2017-5957
Mitre link : CVE-2017-5957
CVE.ORG link : CVE-2017-5957
JSON object : View
Products Affected
                virglrenderer_project
- virglrenderer
qemu
- qemu
CWE
                
                    
                        
                        CWE-787
                        
            Out-of-bounds Write
