Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Virglrenderer Project

First CVE: Mar 14, 2017Active for: 9 yearsTotal CVEs: 20
20.0
VTI Score
Low

Virglrenderer is a specialized graphics virtualization library that provides GPU rendering capabilities for virtual machines and hypervisor-based workloads, with a narrow product scope centered on the virglrenderer project itself. Although the project maintains a modest CVE volume, its role in virtualization infrastructure positions it among more prominent components in the landscape. The vendor's vulnerability profile is characterized by memory-safety and resource-management weaknesses, including NULL pointer dereferences, out-of-bounds reads and writes, buffer-boundary violations, and resource-lifetime issues that are inherent to a C-based graphics rendering engine. Defenders should monitor this vendor's advisories for environments where GPU virtualization is in use and treat updates as part of hypervisor security maintenance cycles. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 96% of tracked vendors
5.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Virglrenderer Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2017
9 years ago
Most Recent CVE
Aug 26, 2022
1,428 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-0135HIGH
An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a specially crafted virgil resource and th
Aug 25, 20227.826NONO
CVE-2019-18389HIGH
A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service
Dec 23, 20197.825NONO
CVE-2017-5580HIGH
The parse_instruction function in gallium/auxiliary/tgsi/tgsi_text.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array acc
Mar 15, 20177.124NONO
CVE-2019-18390HIGH
An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_B
Dec 23, 20197.123NONO
CVE-2016-10214MEDIUM
Memory leak in the virgl_resource_attach_backing function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (memory consumption) via a large nu
Mar 20, 20176.522NONO
CVE-2020-8003MEDIUM
A double-free vulnerability in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of service by triggering texture allocation failure, because vrend
Jan 27, 20205.521NONO
CVE-2017-5937MEDIUM
The util_format_is_pure_uint function in vrend_renderer.c in Virgil 3d project (aka virglrenderer) 0.6.0 and earlier allows local guest OS users to cause a denial of service (NULL
Mar 15, 20176.521NONO
CVE-2017-6386MEDIUM
Memory leak in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer allows local guest OS users to cause a denial of service (host memory consumptio
Mar 15, 20176.521NONO
CVE-2017-6317MEDIUM
Memory leak in the add_shader_program function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption)
Mar 15, 20176.521NONO
CVE-2017-6210MEDIUM
The vrend_decode_reset function in vrend_decode.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (NULL pointer dereference and QEMU process
Mar 15, 20176.521NONO
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
80%
20%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local20 (100.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None20 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low19 (95.0%)
High0 (0.0%)
None1 (5.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Virglrenderer Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Virglrenderer Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Virglrenderer Project's Products

View all 2 CNAs →

Top CWEs