CVE-2016-10163Missing Release of Memory after Effective Lifetime in Project Virglrenderer

CWE-3997 documents6 sources
Severity
6.5MEDIUMNVD
EPSS
0.1%
top 81.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 15
Latest updateMay 17

Description

Memory leak in the vrend_renderer_context_create_internal function in vrend_decode.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) by repeatedly creating a decode context.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:HExploitability: 2.0 | Impact: 4.0

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-rrpr-p3gr-w324: Memory leak in the vrend_renderer_context_create_internal function in vrend_decode2022-05-17
CVEList
CVE-2016-10163: Memory leak in the vrend_renderer_context_create_internal function in vrend_decode2017-03-15
OSV
CVE-2016-10163: Memory leak in the vrend_renderer_context_create_internal function in vrend_decode2017-03-15

📋Vendor Advisories

1
Debian
CVE-2016-10163: virglrenderer - Memory leak in the vrend_renderer_context_create_internal function in vrend_deco...2016

💬Community

2
Bugzilla
CVE-2016-10163 Virglrenderer: host memory leakage when creating decode context [fedora-all]2017-01-24
Bugzilla
CVE-2016-10163 Virglrenderer: host memory leakage when creating decode context2017-01-24
CVE-2016-10163 — Project Virglrenderer vulnerability | cvebase