Virglrenderer is a specialized graphics virtualization library that provides GPU rendering capabilities for virtual machines and hypervisor-based workloads, with a narrow product scope centered on the virglrenderer project itself. Although the project maintains a modest CVE volume, its role in virtualization infrastructure positions it among more prominent components in the landscape. The vendor's vulnerability profile is characterized by memory-safety and resource-management weaknesses, including NULL pointer dereferences, out-of-bounds reads and writes, buffer-boundary violations, and resource-lifetime issues that are inherent to a C-based graphics rendering engine. Defenders should monitor this vendor's advisories for environments where GPU virtualization is in use and treat updates as part of hypervisor security maintenance cycles. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Virglrenderer Project over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0135HIGH An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a specially crafted virgil resource and th | Aug 25, 2022 | 7.8 | 26 | NO | NO |
CVE-2019-18389HIGH A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service | Dec 23, 2019 | 7.8 | 25 | NO | NO |
CVE-2017-5580HIGH The parse_instruction function in gallium/auxiliary/tgsi/tgsi_text.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array acc | Mar 15, 2017 | 7.1 | 24 | NO | NO |
CVE-2019-18390HIGH An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_B | Dec 23, 2019 | 7.1 | 23 | NO | NO |
CVE-2016-10214MEDIUM Memory leak in the virgl_resource_attach_backing function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (memory consumption) via a large nu | Mar 20, 2017 | 6.5 | 22 | NO | NO |
CVE-2020-8003MEDIUM A double-free vulnerability in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of service by triggering texture allocation failure, because vrend | Jan 27, 2020 | 5.5 | 21 | NO | NO |
CVE-2017-5937MEDIUM The util_format_is_pure_uint function in vrend_renderer.c in Virgil 3d project (aka virglrenderer) 0.6.0 and earlier allows local guest OS users to cause a denial of service (NULL | Mar 15, 2017 | 6.5 | 21 | NO | NO |
CVE-2017-6386MEDIUM Memory leak in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer allows local guest OS users to cause a denial of service (host memory consumptio | Mar 15, 2017 | 6.5 | 21 | NO | NO |
CVE-2017-6317MEDIUM Memory leak in the add_shader_program function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) | Mar 15, 2017 | 6.5 | 21 | NO | NO |
CVE-2017-6210MEDIUM The vrend_decode_reset function in vrend_decode.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (NULL pointer dereference and QEMU process | Mar 15, 2017 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Virglrenderer Project.
Media articles that mention a CVE ID that affects a product developed by Virglrenderer Project — matched by CVE ID, not by vendor name.