SUSE SLED12 / SLES12 Security Update : virglrenderer (SUSE-SU-2017:0798-1)

Medium Nessus Plugin ID 97913


The remote SUSE host is missing one or more security updates.


This update for virglrenderer fixes the following issues: Security issues fixed :

- CVE-2017-6386: memory leakage while in vrend_create_vertex_elements_state (bsc#1027376)

- CVE-2017-6355: integer overflow while creating shader object (bsc#1027108)

- CVE-2017-6317: fix memory leak in add shader program (bsc#1026922)

- CVE-2017-6210: NULL pointer dereference in vrend_decode_reset (bsc#1026725)

- CVE-2017-6209: stack buffer oveflow in parse_identifier (bsc#1026723)

- CVE-2017-5994: out-of-bounds access in vrend_create_vertex_elements_state (bsc#1025507)

- CVE-2017-5993: host memory leakage when initialising blitter context (bsc#1025505)

- CVE-2017-5957: stack overflow in vrend_decode_set_framebuffer_state (bsc#1024993)

- CVE-2017-5956: OOB access while in vrend_draw_vbo (bsc#1024992)

- CVE-2017-5937: NULL pointer dereference in vrend_clear (bsc#1024232)

- CVE-2017-5580: OOB access while parsing texture instruction (bsc#1021627)

- CVE-2016-10214: host memory leak issue in virgl_resource_attach_backing (bsc#1024244)

- CVE-2016-10163: host memory leakage when creating decode context (bsc#1021616)

Note that Tenable Network Security has extracted the preceding description block directly from the SUSE security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.


To install this SUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product :

SUSE Linux Enterprise Software Development Kit 12-SP2:zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-452=1

SUSE Linux Enterprise Server for Raspberry Pi 12-SP2:zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-452=1

SUSE Linux Enterprise Server 12-SP2:zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-452=1

SUSE Linux Enterprise Desktop 12-SP2:zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-452=1

To bring your system up-to-date, use 'zypper patch'.

See Also

Plugin Details

Severity: Medium

ID: 97913

File Name: suse_SU-2017-0798-1.nasl

Version: $Revision: 3.2 $

Type: local

Agent: unix

Published: 2017/03/23

Modified: 2017/08/16

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 4.9

Temporal Score: 3.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Temporal Vector: CVSS2#E:U/RL:OF/RC:C


Base Score: 7.1

Temporal Score: 6.2

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:libvirglrenderer0, p-cpe:/a:novell:suse_linux:libvirglrenderer0-debuginfo, p-cpe:/a:novell:suse_linux:virglrenderer-debugsource, cpe:/o:novell:suse_linux:12

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2017/03/22

Reference Information

CVE: CVE-2016-10163, CVE-2016-10214, CVE-2017-5580, CVE-2017-5937, CVE-2017-5956, CVE-2017-5957, CVE-2017-5993, CVE-2017-5994, CVE-2017-6209, CVE-2017-6210, CVE-2017-6317, CVE-2017-6355, CVE-2017-6386

OSVDB: 150798, 150911, 151849, 151852, 151924, 151925, 152151, 152152, 152468, 152476, 152522, 152618, 152706