An out-of-bounds read in the vrendblitneedswizzle function in vrendrenderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGLCCMDBLIT commands.
[
{
"source": "https://gitlab.freedesktop.org/virgl/virglrenderer@24f67de7a9088a873844a39be03cee6882260ac9",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "src/virgl_hw.h"
},
"id": "CVE-2019-18390-1dd0f6fb",
"digest": {
"threshold": 0.9,
"line_hashes": [
"295718410517094950528114583803510995894",
"43468277317181871649856080072575986996",
"249655131899309062348327631190168477966"
]
},
"signature_type": "Line"
},
{
"source": "https://gitlab.freedesktop.org/virgl/virglrenderer@24f67de7a9088a873844a39be03cee6882260ac9",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "src/vrend_renderer.c"
},
"id": "CVE-2019-18390-6bbeadc1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"203327541951848299864613017926910193462",
"42597155943745953960949306703066152174",
"163259354468978262870234779266794485686",
"104382142299863661724756600661953964042",
"195073412259000187659366091482833080495",
"221501829541838785924229101314879422744",
"272004653704100493015803223915055268624"
]
},
"signature_type": "Line"
},
{
"source": "https://gitlab.freedesktop.org/virgl/virglrenderer@24f67de7a9088a873844a39be03cee6882260ac9",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "vrend_renderer_blit",
"file": "src/vrend_renderer.c"
},
"id": "CVE-2019-18390-e6c43cf8",
"digest": {
"length": 2421.0,
"function_hash": "103917660898869094351024064010480370128"
},
"signature_type": "Function"
}
]