Stack-based buffer overflow in the vrenddecodesetframebufferstate function in vrenddecode.c in virglrenderer before 926b9b3460a48f6454d8bbe9e44313d86a65447f, as used in Quick Emulator (QEMU), allows a local guest users to cause a denial of service (application crash) via the "nrcbufs" argument.