Memory leak in the add_shader_program function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) via vectors involving the sprog variable.
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
Link | Tags |
---|---|
https://security.gentoo.org/glsa/201707-06 | vendor advisory |
https://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.html | mailing list patch |
http://www.openwall.com/lists/oss-security/2017/02/24/5 | mailing list patch |
https://cgit.freedesktop.org/virglrenderer/commit/?id=a2f12a1b0f95b13b6f8dc3d05d7b74b4386394e4 | patch |
https://bugzilla.redhat.com/show_bug.cgi?id=1426756 | issue tracking patch |
http://www.securityfocus.com/bid/96450 | vdb entry third party advisory |