CVE-2017-5994 is a heap-based buffer overflow vulnerability in the virglrenderer project, specifically affecting versions prior to 0.6.0. It allows a local guest OS user to trigger an out-of-bounds array access and cause a denial of service (crash) by manipulating the num_elements parameter in the vrend_create_vertex_elements_state function. This vulnerability is rated Medium severity (CVSS 5.5) with a low attack complexity, requiring local access and no user interaction, leading to a high impact on availability. There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.5.0CPE matchmatch criteria | cpe:2.3:a:virglrenderer_project:virglrenderer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.