The virtiogpusetscanout function in QEMU (aka Quick Emulator) built with Virtio GPU Device emulator support allows local guest OS users to cause a denial of service (out-of-bounds read and process crash) via a scanout id in a VIRTIOGPUCMDSETSCANOUT command larger than numscanouts.