Source: virglrenderer
Version: 1.1.0-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for virglrenderer.

CVE-2025-2509[0]:
| Out-of-Bounds Read in Virglrenderer in ChromeOS  16093.57.0 allows a
| malicious guest VM to achieve arbitrary address access within the
| crosvm sandboxed process, potentially leading to  VM escape via
| crafted vertex elements data triggering an out-of-bounds read in
| util_format_description.

Unfortunately we have not really much information here, and the
chromium issuetracker issues are not accessible.

It *mgiht* be ChromeOS specific, but this needs to be assessed, can
you reach out to upstream?


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-2509
    https://www.cve.org/CVERecord?id=CVE-2025-2509

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to