CVE-2017-6210NULL Pointer Dereference in Project Virglrenderer

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 79.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 15
Latest updateMay 17

Description

The vrend_decode_reset function in vrend_decode.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (NULL pointer dereference and QEMU process crash) by destroying context 0 (zero).

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:HExploitability: 2.0 | Impact: 4.0

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-c3q9-4cx6-6r4j: The vrend_decode_reset function in vrend_decode2022-05-17
CVEList
CVE-2017-6210: The vrend_decode_reset function in vrend_decode2017-03-15
OSV
CVE-2017-6210: The vrend_decode_reset function in vrend_decode2017-03-15

📋Vendor Advisories

1
Debian
CVE-2017-6210: virglrenderer - The vrend_decode_reset function in vrend_decode.c in virglrenderer before 0.6.0 ...2017

💬Community

1
Bugzilla
CVE-2017-6210 Virglrenderer: null pointer dereference in vrend_decode_reset2017-02-23
CVE-2017-6210 — NULL Pointer Dereference | cvebase