Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:26184
HistoryAug 06, 2020 - 9:34 p.m.

Arbitrary Code Execution

2020-08-0621:34:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
arbitrary code execution
denial of service
guest os
software vulnerability
heap-based buffer overflow

EPSS

0.001

Percentile

19.0%

virglrenderer is vulnerable to arbitrary code execution. A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c allows guest OS users to cause a denial of service condition and execute arbitrary code via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.