7.1
CVSSv3

CVE-2017-5580

Published: 15/03/2017 Updated: 11/07/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.1 | Impact Score: 4 | Exploitability Score: 2.5
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The parse_instruction function in gallium/auxiliary/tgsi/tgsi_text.c in virglrenderer prior to 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and process crash) via a crafted texture instruction.

Vulnerable Product Search on Vulmon Subscribe to Product

virglrenderer project virglrenderer

Vendor Advisories

Debian Bug report logs - #852604 virglrenderer: CVE-2017-5580 Package: src:virglrenderer; Maintainer for src:virglrenderer is Gert Wollny <gewo@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 25 Jan 2017 14:57:01 UTC Severity: grave Tags: security, upstream Found in version virglrendere ...
The parse_instruction function in gallium/auxiliary/tgsi/tgsi_textc in virglrenderer before 060 allows local guest OS users to cause a denial of service (out-of-bounds array access and process crash) via a crafted texture instruction ...