CVE-2017-5957

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
14/03/2017
Last modified:
20/04/2025

Description

Stack-based buffer overflow in the vrend_decode_set_framebuffer_state function in vrend_decode.c in virglrenderer before 926b9b3460a48f6454d8bbe9e44313d86a65447f, as used in Quick Emulator (QEMU), allows a local guest users to cause a denial of service (application crash) via the "nr_cbufs" argument.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:virglrenderer_project:virglrenderer:*:*:*:*:*:*:*:* 0.6.0 (excluding)
cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*