Integer overflow in the vrend_create_shader function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (process crash) via crafted pkt_length and offlen values, which trigger an out-of-bounds access.
| Software | From | Fixed in |
|---|---|---|
| freedesktop / virglrenderer | - | 0.5.0.x |