Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <a5d4cb3c0ee94490ae2c932b076f42a6@imshyb01.MITRE.ORG>
Date: Wed, 25 Jan 2017 03:43:30 -0500
From: <cve-assign@...re.org>
To: <ppandit@...hat.com>
CC: <cve-assign@...re.org>, <oss-security@...ts.openwall.com>,
	<liqiang6-s@....cn>
Subject: Re: CVE request Virglrenderer: host memory leakage when creating decode context

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

> Virgil 3d project, used by Quick Emulator(Qemu) to implement 3D GPU support
> for the virtio GPU, is vulnerable to memory leakage issue. It could occur when
> a guest tries to create decode context via 'VIRTIO_GPU_CMD_CTX_CREATE'
> command.
> 
> A guest user/process could use this flaw to leak host memory resulting in DoS.
> 
> https://cgit.freedesktop.org/virglrenderer/commit/?id=747a293ff6055203e529f083896b823e22523fe7
> https://bugzilla.redhat.com/show_bug.cgi?id=1415944

Use CVE-2016-10163.

- -- 
CVE Assignment Team
M/S M300, 202 Burlington Road, Bedford, MA 01730 USA
[ A PGP key is available for encrypted communications at
  http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJYiGPEAAoJEHb/MwWLVhi2YPwP/1lOP3BYfiiEYcQIfnmTdDII
r9Vh3OY9OQGN1gpUepaTGOgINwO5Pue9JI7mQaBEf7aV2eWnQjmqs+HDHhqAT2RA
vPo+LeRqDKwe8kMRF/cxW0HYHo3lw8mIE6dXiwQNYz2R0vGmNMfLwpx1F5oPzqFP
YDcBFqhonAVcHZwAtfnqqD0RmFLCv9kn6MEH0J5Pjzc3aE7nrefynPyjtoIfKWb3
PuahXTdR458uq8GodQemjoamesqEFBCdWim3ycTQrNF6Z5TzBTtzdjuWAhUJ8fN0
GRrDHpVtSSiJcUqlZziz3W0tv1LPUtYutcG1bluxOrCHEATJSrvpkRaP70hp0E94
sOcYQ7Gs+uBWgYOKkurG0msq+/Hn60KwNr4omciA2LD3X3ehPl3BcN1YvRBxTt6r
c4wNfEpZAZasz1A6GRnhDBmtTg/KXf30y+/FY5WQ6X6QEkd9elSD0reNAyL+y/Ul
kx4djZxCGd0mBkp95n90QOZEwXvlxj9wagqGJaz9DF93Y5vBrTop33gRW6pszbid
JqPf1HuGb0I/azGvKLSZNQzHzTJ57QESGJhjiNTk9rdc0sw4notWd4qTZ4P/tt73
1dYooaV31dFKqe1LUm6iaLCG0/FU5xYOHTFe+MeUZDxeo332Cw431+JNgyv7ZuDy
o7wPhJVeTbxHkNmYV/tm
=ak6W
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.