An out-of-bounds read in the vrendblitneedswizzle function in vrendrenderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGLCCMDBLIT commands.
{ "vanir_signatures": [ { "digest": { "line_hashes": [ "295718410517094950528114583803510995894", "43468277317181871649856080072575986996", "249655131899309062348327631190168477966" ], "threshold": 0.9 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2019-18390-1dd0f6fb", "source": "https://gitlab.freedesktop.org/virgl/virglrenderer@24f67de7a9088a873844a39be03cee6882260ac9", "signature_type": "Line", "target": { "file": "src/virgl_hw.h" } }, { "digest": { "line_hashes": [ "203327541951848299864613017926910193462", "42597155943745953960949306703066152174", "163259354468978262870234779266794485686", "104382142299863661724756600661953964042", "195073412259000187659366091482833080495", "221501829541838785924229101314879422744", "272004653704100493015803223915055268624" ], "threshold": 0.9 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2019-18390-6bbeadc1", "source": "https://gitlab.freedesktop.org/virgl/virglrenderer@24f67de7a9088a873844a39be03cee6882260ac9", "signature_type": "Line", "target": { "file": "src/vrend_renderer.c" } }, { "digest": { "function_hash": "103917660898869094351024064010480370128", "length": 2421.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2019-18390-e6c43cf8", "source": "https://gitlab.freedesktop.org/virgl/virglrenderer@24f67de7a9088a873844a39be03cee6882260ac9", "signature_type": "Function", "target": { "file": "src/vrend_renderer.c", "function": "vrend_renderer_blit" } } ] }