A heap-based buffer overflow flaw was found in virglrenderer. The vrend_renderer_transfer_write_iov function allows guest OS users to cause a denial of service or a QEMU guest-to-host escape with code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as to system availability.