File _patchinfo of Package patchinfo.6553
<patchinfo incident="6553">
<issue id="1021616" tracker="bnc">VUL-1: CVE-2016-10163: virglrenderer: host memory leakage when creating decode context</issue>
<issue id="1021627" tracker="bnc">VUL-1: CVE-2017-5580: virglrenderer: OOB access while parsing texture instruction</issue>
<issue id="1024232" tracker="bnc">VUL-1: CVE-2017-5937: virglrenderer: null pointer dereference in vrend_clear</issue>
<issue id="1024244" tracker="bnc">VUL-1: CVE-2016-10214: virglrenderer: host memory leak issue in virgl_resource_attach_backing</issue>
<issue id="1024992" tracker="bnc">VUL-0: CVE-2017-5956: virglrenderer: OOB access while in vrend_draw_vbo</issue>
<issue id="1024993" tracker="bnc">VUL-0: CVE-2017-5957: virglrenderer: stack overflow in vrend_decode_set_framebuffer_state</issue>
<issue id="1025505" tracker="bnc">VUL-0: CVE-2017-5993: virglrenderer: host memory leakage when initialising blitter context</issue>
<issue id="1025507" tracker="bnc">VUL-0: CVE-2017-5994: virglrenderer: out-of-bounds access in vrend_create_vertex_elements_state</issue>
<issue id="1026723" tracker="bnc">VUL-0: CVE-2017-6209: virglrenderer: stack buffer oveflow in parse_identifier</issue>
<issue id="1026725" tracker="bnc">VUL-0: CVE-2017-6210: virglrenderer: null pointer dereference in vrend_decode_reset</issue>
<issue id="1027108" tracker="bnc">VUL-0: CVE-2017-6355: virglrenderer: integer overflow while creating shader object</issue>
<issue id="1027376" tracker="bnc">VUL-0: CVE-2017-6386: virglrenderer: memory leakage while in vrend_create_vertex_elements_state</issue>
<issue id="1026922" tracker="bnc">VUL-0: CVE-2017-6317: virglrenderer: memory leakage issue in add_shader_program</issue>
<issue id="2016-10163" tracker="cve" />
<issue id="2016-10214" tracker="cve" />
<issue id="2017-5580" tracker="cve" />
<issue id="2017-5937" tracker="cve" />
<issue id="2017-5956" tracker="cve" />
<issue id="2017-5957" tracker="cve" />
<issue id="2017-5993" tracker="cve" />
<issue id="2017-5994" tracker="cve" />
<issue id="2017-6209" tracker="cve" />
<issue id="2017-6210" tracker="cve" />
<issue id="2017-6317" tracker="cve" />
<issue id="2017-6355" tracker="cve" />
<issue id="2017-6386" tracker="cve" />
<category>security</category>
<rating>moderate</rating>
<packager>lin_ma</packager>
<description>This update for virglrenderer fixes the following issues:
Security issues fixed:
- CVE-2017-6386: memory leakage while in vrend_create_vertex_elements_state (bsc#1027376)
- CVE-2017-6355: integer overflow while creating shader object (bsc#1027108)
- CVE-2017-6317: fix memory leak in add shader program (bsc#1026922)
- CVE-2017-6210: null pointer dereference in vrend_decode_reset (bsc#1026725)
- CVE-2017-6209: stack buffer oveflow in parse_identifier (bsc#1026723)
- CVE-2017-5994: out-of-bounds access in vrend_create_vertex_elements_state (bsc#1025507)
- CVE-2017-5993: host memory leakage when initialising blitter context (bsc#1025505)
- CVE-2017-5957: stack overflow in vrend_decode_set_framebuffer_state (bsc#1024993)
- CVE-2017-5956: OOB access while in vrend_draw_vbo (bsc#1024992)
- CVE-2017-5937: null pointer dereference in vrend_clear (bsc#1024232)
- CVE-2017-5580: OOB access while parsing texture instruction (bsc#1021627)
- CVE-2016-10214: host memory leak issue in virgl_resource_attach_backing (bsc#1024244)
- CVE-2016-10163: host memory leakage when creating decode context (bsc#1021616)
This update was imported from the SUSE:SLE-12-SP2:Update update project.</description>
<summary>Security update for virglrenderer</summary>
</patchinfo>