A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service, or QEMU guest-to-host escape and code execution, via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.
References
Configurations
History
No history.
Information
Published : 2019-12-23 16:15
Updated : 2024-11-21 04:33
NVD link : CVE-2019-18389
Mitre link : CVE-2019-18389
CVE.ORG link : CVE-2019-18389
JSON object : View
Products Affected
debian
- debian_linux
redhat
- enterprise_linux
virglrenderer_project
- virglrenderer
opensuse
- leap
CWE
CWE-787
Out-of-bounds Write