UbuntuUpdates.org

Package "virglrenderer"

Name: virglrenderer

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • virtual GPU for KVM virtualization - headers
  • virtual GPU for KVM virtualization

Latest version: 0.8.2-1ubuntu1.1
Release: focal (20.04)
Level: security
Repository: main

Links



Other versions of "virglrenderer" in Focal

Repository Area Version
base main 0.8.2-1ubuntu1
security universe 0.8.2-1ubuntu1.1
updates main 0.8.2-1ubuntu1.1
updates universe 0.8.2-1ubuntu1.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 0.8.2-1ubuntu1.1 2022-02-28 19:06:24 UTC

  virglrenderer (0.8.2-1ubuntu1.1) focal-security; urgency=medium

  * SECURITY UPDATE: out-of-bounds write in read_transfer_data()
    - debian/patches/CVE-2022-0135.patch: Add test to resource OOB write
      and fix it in src/vrend_renderer.c, tests/test_fuzzer_formats.c.
    - CVE-2022-0135
  * SECURITY UPDATE: info leak in vrend_resource_alloc_buffer()
    - debian/patches/CVE-2022-0175.patch: clear memory when allocating a
      host-backed memory resource in src/vrend_renderer.c,
      tests/test_virgl_transfer.c.
    - CVE-2022-0175

 -- Marc Deslauriers <email address hidden> Wed, 23 Feb 2022 10:49:14 -0500

CVE-2022-0135 out-of-bounds write in read_transfer_data()
CVE-2022-0175 memory initialization issue in vrend_resource_alloc_buffer() can lead to info leak



About   -   Send Feedback to @ubuntu_updates