Bug ID 1162521
Summary VUL-1: CVE-2020-8003: virglrenderer: Double-free vulnerability in vrend_renderer.c
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.3
Hardware Other
URL https://smash.suse.de/issue/251890/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Security
Assignee brogers@suse.com
Reporter atoptsoglou@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2020-8003

A double-free vulnerability in vrend_renderer.c in virglrenderer through 0.8.1
allows attackers to cause a denial of service by triggering texture allocation
failure, because vrend_renderer_resource_allocated_texture is not an
appropriate place for a free.

References:

https://gitlab.freedesktop.org/virgl/virglrenderer/commit/f9b079ccc319c98499111f66bd654fc9b56cf15f?merge_request_iid=340
https://gitlab.freedesktop.org/virgl/virglrenderer/merge_requests/340
https://gitlab.freedesktop.org/virgl/virglrenderer/merge_requests/340/diffs?commit_id=3320973c9f2068f60cf6613c2811a8824781878a
https://gitlab.freedesktop.org/virgl/virglrenderer/merge_requests/340/diffs?commit_id=f9b079ccc319c98499111f66bd654fc9b56cf15f

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1796643
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-8003
http://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-8003.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8003
https://gitlab.freedesktop.org/virgl/virglrenderer/commit/f9b079ccc319c98499111f66bd654fc9b56cf15f?merge_request_iid=340
https://gitlab.freedesktop.org/virgl/virglrenderer/merge_requests/340/diffs?commit_id=3320973c9f2068f60cf6613c2811a8824781878a
https://gitlab.freedesktop.org/virgl/virglrenderer/merge_requests/340/diffs?commit_id=f9b079ccc319c98499111f66bd654fc9b56cf15f
https://gitlab.freedesktop.org/virgl/virglrenderer/merge_requests/340


You are receiving this mail because: