SUSE-SU-2017:0798-1

Source
https://www.suse.com/support/update/announcement/2017/suse-su-20170798-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:0798-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2017:0798-1
Related
Published
2017-03-22T14:57:19Z
Modified
2017-03-22T14:57:19Z
Summary
Security update for virglrenderer
Details

This update for virglrenderer fixes the following issues:

Security issues fixed: - CVE-2017-6386: memory leakage while in vrendcreatevertexelementsstate (bsc#1027376) - CVE-2017-6355: integer overflow while creating shader object (bsc#1027108) - CVE-2017-6317: fix memory leak in add shader program (bsc#1026922) - CVE-2017-6210: null pointer dereference in vrenddecodereset (bsc#1026725) - CVE-2017-6209: stack buffer oveflow in parseidentifier (bsc#1026723) - CVE-2017-5994: out-of-bounds access in vrendcreatevertexelementsstate (bsc#1025507) - CVE-2017-5993: host memory leakage when initialising blitter context (bsc#1025505) - CVE-2017-5957: stack overflow in vrenddecodesetframebufferstate (bsc#1024993) - CVE-2017-5956: OOB access while in vrenddrawvbo (bsc#1024992) - CVE-2017-5937: null pointer dereference in vrendclear (bsc#1024232) - CVE-2017-5580: OOB access while parsing texture instruction (bsc#1021627) - CVE-2016-10214: host memory leak issue in virglresourceattach_backing (bsc#1024244) - CVE-2016-10163: host memory leakage when creating decode context (bsc#1021616)

References

Affected packages

SUSE:Linux Enterprise Desktop 12 SP2 / virglrenderer

Package

Name
virglrenderer
Purl
pkg:rpm/suse/virglrenderer&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-11.1

Ecosystem specific

{
    "binaries": [
        {
            "libvirglrenderer0": "0.5.0-11.1"
        }
    ]
}

SUSE:Linux Enterprise Server for Raspberry Pi 12 SP2 / virglrenderer

Package

Name
virglrenderer
Purl
pkg:rpm/suse/virglrenderer&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-11.1

Ecosystem specific

{
    "binaries": [
        {
            "libvirglrenderer0": "0.5.0-11.1"
        }
    ]
}

SUSE:Linux Enterprise Software Development Kit 12 SP2 / virglrenderer

Package

Name
virglrenderer
Purl
pkg:rpm/suse/virglrenderer&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-11.1

Ecosystem specific

{
    "binaries": [
        {
            "virglrenderer-devel": "0.5.0-11.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP2 / virglrenderer

Package

Name
virglrenderer
Purl
pkg:rpm/suse/virglrenderer&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-11.1

Ecosystem specific

{
    "binaries": [
        {
            "libvirglrenderer0": "0.5.0-11.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP2 / virglrenderer

Package

Name
virglrenderer
Purl
pkg:rpm/suse/virglrenderer&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-11.1

Ecosystem specific

{
    "binaries": [
        {
            "libvirglrenderer0": "0.5.0-11.1"
        }
    ]
}