4.9
CVSSv2

CVE-2016-10163

Published: 15/03/2017 Updated: 11/07/2017
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.5 | Impact Score: 4 | Exploitability Score: 2
VMScore: 436
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Memory leak in the vrend_renderer_context_create_internal function in vrend_decode.c in virglrenderer prior to 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) by repeatedly creating a decode context.

Vulnerable Product Search on Vulmon Subscribe to Product

virglrenderer project virglrenderer

Vendor Advisories

Debian Bug report logs - #852603 virglrenderer: CVE-2016-10163 Package: src:virglrenderer; Maintainer for src:virglrenderer is Gert Wollny <gewo@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 25 Jan 2017 14:54:02 UTC Severity: grave Tags: patch, security, upstream Found in version virg ...
Memory leak in the vrend_renderer_context_create_internal function in vrend_decodec in virglrenderer before 060 allows local guest OS users to cause a denial of service (host memory consumption) by repeatedly creating a decode context ...